// #MalwareMustDie! // Below is the registry information slupred by Fareit in Pony Case "14:59:27.1045335","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Invoice_06202013_2QBK.exe","NAME NOT FOUND","Desired Access: Read" "14:59:27.1318297","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","NAME NOT FOUND","Desired Access: Query Value, Set Value" "14:59:27.1319864","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","NAME NOT FOUND","Desired Access: Query Value" "14:59:27.1594793","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msvcrt.dll","NAME NOT FOUND","Desired Access: Read" "14:59:27.1601154","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secur32.dll","NAME NOT FOUND","Desired Access: Read" "14:59:27.1601780","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RPCRT4.dll","NAME NOT FOUND","Desired Access: Read" "14:59:27.1602274","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ADVAPI32.dll","NAME NOT FOUND","Desired Access: Read" "14:59:27.1618950","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\LeakTrack","NAME NOT FOUND","Length: 144" "14:59:27.1619841","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Diagnostics","NAME NOT FOUND","Desired Access: Read" "14:59:27.1620439","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GDI32.dll","NAME NOT FOUND","Desired Access: Read" "14:59:27.1620869","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\USER32.dll","NAME NOT FOUND","Desired Access: Read" "14:59:27.1622657","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\SafeDllSearchMode","NAME NOT FOUND","Length: 16" "14:59:27.2402848","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IMM32.DLL","NAME NOT FOUND","Desired Access: Read" "14:59:27.2495877","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntdll.dll","NAME NOT FOUND","Desired Access: Read" "14:59:27.2496209","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kernel32.dll","NAME NOT FOUND","Desired Access: Read" "14:59:27.2496491","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSFTEDIT.dll","NAME NOT FOUND","Desired Access: Read" "14:59:27.2497000","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SHLWAPI.dll","NAME NOT FOUND","Desired Access: Read" "14:59:27.2497274","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SHELL32.dll","NAME NOT FOUND","Desired Access: Read" "14:59:27.2497539","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASN1.dll","NAME NOT FOUND","Desired Access: Read" "14:59:27.2518564","RegOpenKey","HKLM\System\CurrentControlSet\Control\Error Message Instrument\","NAME NOT FOUND","Desired Access: Read" "14:59:27.2519508","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles","NAME NOT FOUND","Length: 20" "14:59:27.2522648","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Compatibility32\Invoice_06202013_2QBK","NAME NOT FOUND","Length: 172" "14:59:27.2523447","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IME Compatibility\Invoice_06202013_2QBK","NAME NOT FOUND","Length: 172" "14:59:27.2621552","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\USP10.dll","NAME NOT FOUND","Desired Access: Read" "14:59:27.2623318","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\LPK.DLL","NAME NOT FOUND","Desired Access: Read" "14:59:27.3077582","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Performance","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:27.3081563","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read" "14:59:27.3081918","RegQueryValue","HKCU\Control Panel\Desktop\MultiUILanguageId","NAME NOT FOUND","Length: 256" "14:59:27.3090631","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read" "14:59:27.3090944","RegQueryValue","HKCU\Control Panel\Desktop\MultiUILanguageId","NAME NOT FOUND","Length: 256" "14:59:27.3375111","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots","NAME NOT FOUND","Desired Access: Enumerate Sub Keys" "14:59:27.3442676","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\comctl32.dll","NAME NOT FOUND","Desired Access: Read" "14:59:27.3443567","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read" "14:59:27.3443922","RegQueryValue","HKCU\Control Panel\Desktop\MultiUILanguageId","NAME NOT FOUND","Length: 256" "14:59:27.3664517","RegQueryValue","HKCU\Control Panel\Desktop\SmoothScroll","NAME NOT FOUND","Length: 144" "14:59:27.3665405","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\EnableBalloonTips","NAME NOT FOUND","Length: 144" "14:59:27.3666523","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack","NO MORE ENTRIES","Index: 1, Length: 220" "14:59:27.3680717","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\comctl32.dll","NAME NOT FOUND","Desired Access: Read" "14:59:27.3683307","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read" "14:59:27.3683640","RegQueryValue","HKCU\Control Panel\Desktop\MultiUILanguageId","NAME NOT FOUND","Length: 256" "14:59:27.3727441","RegQueryValue","HKCU\Control Panel\Desktop\SmoothScroll","NAME NOT FOUND","Length: 144" "14:59:32.6990465","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ole32.dll","NAME NOT FOUND","Desired Access: Read" "14:59:32.9398665","RegQueryValue","HKLM\SOFTWARE\Microsoft\Ole\RWLockResourceTimeOut","NAME NOT FOUND","Length: 144" "14:59:32.9418631","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CRYPT32.dll","NAME NOT FOUND","Desired Access: Read" "14:59:32.9419477","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\crypt32\Performance","NAME NOT FOUND","Desired Access: Read" "14:59:32.9430948","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\msasn1","NAME NOT FOUND","Desired Access: Read" "14:59:32.9448453","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OLEAUT32.dll","NAME NOT FOUND","Desired Access: Read" "14:59:32.9449311","RegOpenKey","HKLM\SOFTWARE\Microsoft\OLEAUT","NAME NOT FOUND","Desired Access: Query Value" "14:59:32.9449892","RegOpenKey","HKLM\SOFTWARE\Microsoft\OLEAUT\UserEra","NAME NOT FOUND","Desired Access: Query Value, Enumerate Sub Keys" "14:59:32.9450146","RegOpenKey","HKLM\SOFTWARE\Microsoft\OLEAUT","NAME NOT FOUND","Desired Access: Query Value" "14:59:32.9450375","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wininet.dll","NAME NOT FOUND","Desired Access: Read" "14:59:32.9452010","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read" "14:59:32.9452577","RegQueryValue","HKCU\Control Panel\Desktop\MultiUILanguageId","NAME NOT FOUND","Length: 256" "14:59:33.0022459","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots","NAME NOT FOUND","Desired Access: Enumerate Sub Keys" "14:59:33.0263210","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VERSION.dll","NAME NOT FOUND","Desired Access: Read" "14:59:33.0263699","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\urlmon.dll","NAME NOT FOUND","Desired Access: Read" "14:59:33.0442110","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read" "14:59:33.0442680","RegQueryValue","HKCU\Control Panel\Desktop\MultiUILanguageId","NAME NOT FOUND","Length: 256" "14:59:33.0977368","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots","NAME NOT FOUND","Desired Access: Enumerate Sub Keys" "14:59:33.1017957","RegOpenKey","HKCU\Software\Classes\PROTOCOLS\Name-Space Handler\","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:33.1019144","RegOpenKey","HKCU\Software\Classes\PROTOCOLS\Name-Space Handler","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:33.1019924","RegEnumKey","HKCR\PROTOCOLS\Name-Space Handler","NO MORE ENTRIES","Index: 1, Length: 288" "14:59:33.1020558","RegOpenKey","HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:33.1020871","RegOpenKey","HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:33.1021527","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\DisableImprovedZoneCheck","NAME NOT FOUND","Length: 144" "14:59:33.1022248","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\","NAME NOT FOUND","Desired Access: Query Value" "14:59:33.1022754","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\","NAME NOT FOUND","Desired Access: Read" "14:59:33.1023058","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\","NAME NOT FOUND","Desired Access: Read" "14:59:33.1023394","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\","NAME NOT FOUND","Desired Access: Read" "14:59:33.1023667","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\","NAME NOT FOUND","Desired Access: Read" "14:59:33.1024000","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:33.1024218","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:33.1024478","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:33.1025039","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:33.1025810","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING\Invoice_06202013_2QBK.exe","NAME NOT FOUND","Length: 144" "14:59:33.1026073","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING\*","NAME NOT FOUND","Length: 144" "14:59:33.1037870","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION\Invoice_06202013_2QBK.exe","NAME NOT FOUND","Length: 144" "14:59:33.1038127","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION\*","NAME NOT FOUND","Length: 144" "14:59:33.1039097","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\Invoice_06202013_2QBK.exe","NAME NOT FOUND","Length: 144" "14:59:33.1039345","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\*","NAME NOT FOUND","Length: 144" "14:59:33.1040242","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING\Invoice_06202013_2QBK.exe","NAME NOT FOUND","Length: 144" "14:59:33.1040491","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING\*","NAME NOT FOUND","Length: 144" "14:59:33.1041410","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\Invoice_06202013_2QBK.exe","NAME NOT FOUND","Length: 144" "14:59:33.1041656","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\*","NAME NOT FOUND","Length: 144" "14:59:33.1042586","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT\Invoice_06202013_2QBK.exe","NAME NOT FOUND","Length: 144" "14:59:33.1042829","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT\*","NAME NOT FOUND","Length: 144" "14:59:33.1043701","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS\Invoice_06202013_2QBK.exe","NAME NOT FOUND","Length: 144" "14:59:33.1055370","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\Invoice_06202013_2QBK.exe","NAME NOT FOUND","Length: 144" "14:59:33.1056627","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\Invoice_06202013_2QBK.exe","NAME NOT FOUND","Length: 144" "14:59:33.1056895","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*","NAME NOT FOUND","Length: 144" "14:59:33.1057417","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND","NAME NOT FOUND","Desired Access: Query Value" "14:59:33.1057658","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL","NAME NOT FOUND","Desired Access: Query Value" "14:59:33.1057881","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL","NAME NOT FOUND","Desired Access: Query Value" "14:59:33.1058110","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD","NAME NOT FOUND","Desired Access: Query Value" "14:59:33.1058331","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT","NAME NOT FOUND","Desired Access: Query Value" "14:59:33.1058946","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\Invoice_06202013_2QBK.exe","NAME NOT FOUND","Length: 144" "14:59:33.1059183","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\*","NAME NOT FOUND","Length: 144" "14:59:33.1063290","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE","NAME NOT FOUND","Desired Access: Query Value" "14:59:33.1063991","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT\Invoice_06202013_2QBK.exe","NAME NOT FOUND","Length: 144" "14:59:33.1064240","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT\*","NAME NOT FOUND","Length: 144" "14:59:33.1064801","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK","NAME NOT FOUND","Desired Access: Query Value" "14:59:33.1065039","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_GET_URL_DOM_FILEPATH_UNENCODED","NAME NOT FOUND","Desired Access: Query Value" "14:59:33.1513900","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WS2HELP.dll","NAME NOT FOUND","Desired Access: Read" "14:59:33.1514375","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WS2_32.dll","NAME NOT FOUND","Desired Access: Read" "14:59:33.1514945","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsock32.dll","NAME NOT FOUND","Desired Access: Read" "14:59:33.1659678","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\userenv.dll","NAME NOT FOUND","Desired Access: Read" "14:59:33.1661095","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserEnvDebugLevel","NAME NOT FOUND","Length: 144" "14:59:33.1662134","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\ChkAccDebugLevel","NAME NOT FOUND","Length: 144" "14:59:33.1686620","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\RsopDebugLevel","NAME NOT FOUND","Length: 144" "14:59:33.1687525","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserEnvDebugLevel","NAME NOT FOUND","Length: 144" "14:59:33.1687757","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\RsopLogging","NAME NOT FOUND","Length: 144" "14:59:33.1688210","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\System","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:33.1688883","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserEnvDebugLevel","NAME NOT FOUND","Length: 144" "14:59:33.1689403","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\System","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:33.2438213","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uxtheme.dll","NAME NOT FOUND","Desired Access: Read" "14:59:33.2439719","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\ThemeManager\Compositing","NAME NOT FOUND","Length: 144" "14:59:33.2455858","RegQueryValue","HKCU\Control Panel\Desktop\LameButtonText","NAME NOT FOUND","Length: 144" "14:59:33.2957676","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSCTF.dll","NAME NOT FOUND","Desired Access: Read" "14:59:33.2976167","RegOpenKey","HKLM\SOFTWARE\Microsoft\CTF\Compatibility\Invoice_06202013_2QBK.exe","NAME NOT FOUND","Desired Access: Read" "14:59:33.2978097","RegQueryValue","HKCU\Keyboard Layout\Toggle\Language Hotkey","NAME NOT FOUND","Length: 144" "14:59:33.2978217","RegQueryValue","HKCU\Keyboard Layout\Toggle\Hotkey","NAME NOT FOUND","Length: 144" "14:59:33.2978324","RegQueryValue","HKCU\Keyboard Layout\Toggle\Layout Hotkey","NAME NOT FOUND","Length: 144" "14:59:33.2987146","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read" "14:59:33.2987492","RegQueryValue","HKCU\Control Panel\Desktop\MultiUILanguageId","NAME NOT FOUND","Length: 256" "14:59:33.2988149","RegQueryValue","HKLM\SOFTWARE\Microsoft\CTF\EnableAnchorContext","NAME NOT FOUND","Length: 144" "14:59:33.2996468","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\netapi32.dll","NAME NOT FOUND","Desired Access: Read" "14:59:33.3340152","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msi.dll","NAME NOT FOUND","Desired Access: Read" "14:59:33.3656049","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ATL.DLL","NAME NOT FOUND","Desired Access: Read" "14:59:33.3675602","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pstorec.dll","NAME NOT FOUND","Desired Access: Read" "14:59:33.6583547","RegOpenKey","HKLM\Software\Microsoft\Rpc\PagedBuffers","NAME NOT FOUND","Desired Access: Read" "14:59:33.6584025","RegQueryValue","HKLM\SOFTWARE\Microsoft\Rpc\MaxRpcSize","NAME NOT FOUND","Length: 144" "14:59:33.6584385","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Invoice_06202013_2QBK.exe\RpcThreadPoolThrottle","NAME NOT FOUND","Desired Access: Read" "14:59:33.6585053","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows NT\Rpc","NAME NOT FOUND","Desired Access: Read" "14:59:33.6642803","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6643437","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6643921","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6644619","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Branding\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6645206","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Branding\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6645684","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Branding\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6649424","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6649966","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6650452","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6651151","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectAnimation\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6651684","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectAnimation\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6655182","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectAnimation\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6655906","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6656445","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6656920","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6657612","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DXM_Runtime\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6658129","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DXM_Runtime\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6659138","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DXM_Runtime\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6659842","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6660375","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6660850","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6661521","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ICW\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6662066","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ICW\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6665197","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ICW\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6665904","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6666404","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6666868","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6667547","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6668050","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6669047","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6669740","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6670248","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6670720","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6671405","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6671930","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6703853","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6704616","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LENOVO.SMIIF\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6704800","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LENOVO.SMIIF\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6705085","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LENOVO.SMIIF\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6705208","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LENOVO.SMIIF\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6707264","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LenovoAutoScrollUtility\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6707437","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LenovoAutoScrollUtility\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6707731","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LenovoAutoScrollUtility\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6707851","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LenovoAutoScrollUtility\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6709748","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6710298","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6710784","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6711482","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MPlayer2\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6711982","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MPlayer2\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6712455","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MPlayer2\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6713131","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetMeeting\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6713645","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetMeeting\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6714122","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetMeeting\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6714824","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OnScreenDisplay\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6714986","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OnScreenDisplay\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6715268","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OnScreenDisplay\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6715388","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OnScreenDisplay\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6717302","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OutlookExpress\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6717832","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OutlookExpress\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6718310","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OutlookExpress\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6718986","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PCHealth\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6719129","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PCHealth\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6719388","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PCHealth\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6719503","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PCHealth\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6720196","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PCHealth\DisplayName","NAME NOT FOUND","Length: 144" "14:59:33.6720682","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PCHealth\DisplayName","NAME NOT FOUND","Length: 144" "14:59:33.6721154","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PCHealth\DisplayName","NAME NOT FOUND","Length: 144" "14:59:33.6726250","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6726761","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6727239","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6727979","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ThinkPad FullScreen Magnifier\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6728152","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ThinkPad FullScreen Magnifier\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6728440","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ThinkPad FullScreen Magnifier\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6728568","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ThinkPad FullScreen Magnifier\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6738388","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{350C97B1-3D7C-4EE8-BAA9-00BCB3D54227}\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6739075","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{350C97B1-3D7C-4EE8-BAA9-00BCB3D54227}\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6739609","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{350C97B1-3D7C-4EE8-BAA9-00BCB3D54227}\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6764291","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9FAC9E5C-0D20-4DBF-AFE5-2E09C52A95A2}\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6764467","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9FAC9E5C-0D20-4DBF-AFE5-2E09C52A95A2}\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6764777","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9FAC9E5C-0D20-4DBF-AFE5-2E09C52A95A2}\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6764908","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9FAC9E5C-0D20-4DBF-AFE5-2E09C52A95A2}\UninstallString","BUFFER OVERFLOW","Length: 144" "14:59:33.6769778","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5}\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6770325","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5}\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6770831","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5}\UninstallString","NAME NOT FOUND","Length: 144" "14:59:33.6771121","RegEnumKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall","NO MORE ENTRIES","Index: 33, Length: 288" "14:59:33.9646677","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\00000009","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:33.9647571","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9647730","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9648546","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9648694","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9649409","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9649560","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9650258","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9650409","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9651110","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9651261","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9651965","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9652113","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9652820","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9652971","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9653678","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9653828","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9654591","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9654739","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9655443","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9655591","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9656295","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9656446","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9657161","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9657315","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9658025","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9658178","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9658949","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9659100","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "14:59:33.9660357","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\00000004","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:33.9662128","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\AddressFamily","NAME NOT FOUND","Length: 144" "14:59:33.9664313","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\AddressFamily","NAME NOT FOUND","Length: 144" "14:59:33.9666498","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\AddressFamily","NAME NOT FOUND","Length: 144" "14:59:33.9668057","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Ws2_32NumHandleBuckets","NAME NOT FOUND","Length: 144" "14:59:33.9671174","RegOpenKey","HKCU\Software\Far\Plugins\FTP\Hosts","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:33.9671331","RegOpenKey","HKCU\Software\Far2\Plugins\FTP\Hosts","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:33.9671490","RegOpenKey","HKCU\Software\Far Manager\Plugins\FTP\Hosts","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:33.9671632","RegOpenKey","HKCU\Software\Far\SavedDialogHistory\FTPHost","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:33.9671761","RegOpenKey","HKCU\Software\Far2\SavedDialogHistory\FTPHost","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:33.9671895","RegOpenKey","HKCU\Software\Far Manager\SavedDialogHistory\FTPHost","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:33.9672200","RegOpenKey","HKCU\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read" "14:59:33.9672339","RegOpenKey","HKCU\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:33.9672465","RegOpenKey","HKCU\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:33.9672588","RegOpenKey","HKLM\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read" "14:59:33.9672842","RegOpenKey","HKLM\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:33.9672959","RegOpenKey","HKLM\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:33.9673085","RegOpenKey","HKCU\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read" "14:59:33.9673211","RegOpenKey","HKCU\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:33.9673331","RegOpenKey","HKCU\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:33.9673445","RegOpenKey","HKLM\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read" "14:59:33.9673566","RegOpenKey","HKLM\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:33.9673677","RegOpenKey","HKLM\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0798728","RegOpenKey","HKCU\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0798887","RegOpenKey","HKCU\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0799016","RegOpenKey","HKCU\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0799139","RegOpenKey","HKLM\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0799259","RegOpenKey","HKLM\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0799373","RegOpenKey","HKLM\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0799499","RegOpenKey","HKCU\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0799625","RegOpenKey","HKCU\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0799745","RegOpenKey","HKCU\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0799862","RegOpenKey","HKLM\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0799980","RegOpenKey","HKLM\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0800094","RegOpenKey","HKLM\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0807604","RegOpenKey","HKCU\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0807746","RegOpenKey","HKCU\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0807872","RegOpenKey","HKCU\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0807992","RegOpenKey","HKLM\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0808109","RegOpenKey","HKLM\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0808224","RegOpenKey","HKLM\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0808344","RegOpenKey","HKCU\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0808470","RegOpenKey","HKCU\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0808590","RegOpenKey","HKCU\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0808704","RegOpenKey","HKLM\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0808816","RegOpenKey","HKLM\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0808931","RegOpenKey","HKLM\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0813481","RegOpenKey","HKCU\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0813624","RegOpenKey","HKCU\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0813747","RegOpenKey","HKCU\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0813867","RegOpenKey","HKLM\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0813981","RegOpenKey","HKLM\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0814096","RegOpenKey","HKLM\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0814219","RegOpenKey","HKCU\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0814342","RegOpenKey","HKCU\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0814465","RegOpenKey","HKCU\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0814579","RegOpenKey","HKLM\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0814694","RegOpenKey","HKLM\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0814808","RegOpenKey","HKLM\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0821133","RegOpenKey","HKCU\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0821273","RegOpenKey","HKCU\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0821399","RegOpenKey","HKCU\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0821519","RegOpenKey","HKLM\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0821636","RegOpenKey","HKLM\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0821751","RegOpenKey","HKLM\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0821876","RegOpenKey","HKCU\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0822002","RegOpenKey","HKCU\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0822125","RegOpenKey","HKCU\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0822240","RegOpenKey","HKLM\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0822354","RegOpenKey","HKLM\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0822469","RegOpenKey","HKLM\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0823533","RegOpenKey","HKCU\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0823670","RegOpenKey","HKCU\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0823796","RegOpenKey","HKCU\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0823921","RegOpenKey","HKCU\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0824044","RegOpenKey","HKCU\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0824164","RegOpenKey","HKCU\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0824290","RegOpenKey","HKCU\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0824410","RegOpenKey","HKCU\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0824530","RegOpenKey","HKCU\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0824653","RegOpenKey","HKCU\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0824773","RegOpenKey","HKCU\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0824893","RegOpenKey","HKCU\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0825011","RegOpenKey","HKLM\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0825125","RegOpenKey","HKLM\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0825237","RegOpenKey","HKLM\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0825352","RegOpenKey","HKLM\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0825463","RegOpenKey","HKLM\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0825578","RegOpenKey","HKLM\Software\Ghisler\Windows Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0825692","RegOpenKey","HKLM\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0825807","RegOpenKey","HKLM\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0825922","RegOpenKey","HKLM\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.0826036","RegOpenKey","HKLM\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read" "14:59:34.0826148","RegOpenKey","HKLM\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.0826260","RegOpenKey","HKLM\Software\Ghisler\Total Commander","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1304622","RegOpenKey","HKCU\Software\GlobalSCAPE\CuteFTP 6 Home\QCToolbar","NAME NOT FOUND","Desired Access: Read" "14:59:34.1304795","RegOpenKey","HKCU\Software\GlobalSCAPE\CuteFTP 6 Home\QCToolbar","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1304935","RegOpenKey","HKCU\Software\GlobalSCAPE\CuteFTP 6 Home\QCToolbar","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1305075","RegOpenKey","HKCU\Software\GlobalSCAPE\CuteFTP 6 Professional\QCToolbar","NAME NOT FOUND","Desired Access: Read" "14:59:34.1305214","RegOpenKey","HKCU\Software\GlobalSCAPE\CuteFTP 6 Professional\QCToolbar","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1305346","RegOpenKey","HKCU\Software\GlobalSCAPE\CuteFTP 6 Professional\QCToolbar","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1305480","RegOpenKey","HKCU\Software\GlobalSCAPE\CuteFTP 7 Home\QCToolbar","NAME NOT FOUND","Desired Access: Read" "14:59:34.1305614","RegOpenKey","HKCU\Software\GlobalSCAPE\CuteFTP 7 Home\QCToolbar","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1305745","RegOpenKey","HKCU\Software\GlobalSCAPE\CuteFTP 7 Home\QCToolbar","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1305879","RegOpenKey","HKCU\Software\GlobalSCAPE\CuteFTP 7 Professional\QCToolbar","NAME NOT FOUND","Desired Access: Read" "14:59:34.1306022","RegOpenKey","HKCU\Software\GlobalSCAPE\CuteFTP 7 Professional\QCToolbar","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1306156","RegOpenKey","HKCU\Software\GlobalSCAPE\CuteFTP 7 Professional\QCToolbar","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1306287","RegOpenKey","HKCU\Software\GlobalSCAPE\CuteFTP 8 Home\QCToolbar","NAME NOT FOUND","Desired Access: Read" "14:59:34.1306424","RegOpenKey","HKCU\Software\GlobalSCAPE\CuteFTP 8 Home\QCToolbar","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1306558","RegOpenKey","HKCU\Software\GlobalSCAPE\CuteFTP 8 Home\QCToolbar","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1306692","RegOpenKey","HKCU\Software\GlobalSCAPE\CuteFTP 8 Professional\QCToolbar","NAME NOT FOUND","Desired Access: Read" "14:59:34.1306829","RegOpenKey","HKCU\Software\GlobalSCAPE\CuteFTP 8 Professional\QCToolbar","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1306963","RegOpenKey","HKCU\Software\GlobalSCAPE\CuteFTP 8 Professional\QCToolbar","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1307094","RegOpenKey","HKCU\Software\GlobalSCAPE\CuteFTP 9\QCToolbar","NAME NOT FOUND","Desired Access: Read" "14:59:34.1307226","RegOpenKey","HKCU\Software\GlobalSCAPE\CuteFTP 9\QCToolbar","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1307354","RegOpenKey","HKCU\Software\GlobalSCAPE\CuteFTP 9\QCToolbar","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1307603","RegOpenKey","HKCU\Software\FlashFXP\3","NAME NOT FOUND","Desired Access: Read" "14:59:34.1307734","RegOpenKey","HKCU\Software\FlashFXP\3","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1307852","RegOpenKey","HKCU\Software\FlashFXP\3","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1307969","RegOpenKey","HKCU\Software\FlashFXP","NAME NOT FOUND","Desired Access: Read" "14:59:34.1308083","RegOpenKey","HKCU\Software\FlashFXP","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1308198","RegOpenKey","HKCU\Software\FlashFXP","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1308315","RegOpenKey","HKCU\Software\FlashFXP\3","NAME NOT FOUND","Desired Access: Read" "14:59:34.1308433","RegOpenKey","HKCU\Software\FlashFXP\3","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1308553","RegOpenKey","HKCU\Software\FlashFXP\3","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1308673","RegOpenKey","HKCU\Software\FlashFXP\3","NAME NOT FOUND","Desired Access: Read" "14:59:34.1308787","RegOpenKey","HKCU\Software\FlashFXP\3","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1308902","RegOpenKey","HKCU\Software\FlashFXP\3","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1309019","RegOpenKey","HKCU\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read" "14:59:34.1309134","RegOpenKey","HKCU\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1309248","RegOpenKey","HKCU\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1309366","RegOpenKey","HKCU\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read" "14:59:34.1309480","RegOpenKey","HKCU\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1309595","RegOpenKey","HKCU\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1309712","RegOpenKey","HKCU\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read" "14:59:34.1309827","RegOpenKey","HKCU\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1309941","RegOpenKey","HKCU\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1310059","RegOpenKey","HKCU\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read" "14:59:34.1310179","RegOpenKey","HKCU\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1310293","RegOpenKey","HKCU\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1310408","RegOpenKey","HKLM\Software\FlashFXP\3","NAME NOT FOUND","Desired Access: Read" "14:59:34.1310600","RegOpenKey","HKLM\Software\FlashFXP\3","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1310712","RegOpenKey","HKLM\Software\FlashFXP\3","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1310821","RegOpenKey","HKLM\Software\FlashFXP","NAME NOT FOUND","Desired Access: Read" "14:59:34.1310927","RegOpenKey","HKLM\Software\FlashFXP","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1311036","RegOpenKey","HKLM\Software\FlashFXP","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1311142","RegOpenKey","HKLM\Software\FlashFXP\3","NAME NOT FOUND","Desired Access: Read" "14:59:34.1311251","RegOpenKey","HKLM\Software\FlashFXP\3","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1311360","RegOpenKey","HKLM\Software\FlashFXP\3","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1311467","RegOpenKey","HKLM\Software\FlashFXP\3","NAME NOT FOUND","Desired Access: Read" "14:59:34.1311575","RegOpenKey","HKLM\Software\FlashFXP\3","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1311684","RegOpenKey","HKLM\Software\FlashFXP\3","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1311793","RegOpenKey","HKLM\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read" "14:59:34.1311908","RegOpenKey","HKLM\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1312017","RegOpenKey","HKLM\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1312123","RegOpenKey","HKLM\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read" "14:59:34.1312229","RegOpenKey","HKLM\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1312335","RegOpenKey","HKLM\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1316369","RegOpenKey","HKLM\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read" "14:59:34.1316503","RegOpenKey","HKLM\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1316612","RegOpenKey","HKLM\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1316721","RegOpenKey","HKLM\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read" "14:59:34.1316830","RegOpenKey","HKLM\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1316939","RegOpenKey","HKLM\Software\FlashFXP\4","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1333154","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read" "14:59:34.1333307","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1333430","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1333550","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read" "14:59:34.1333668","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1333785","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1333902","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read" "14:59:34.1334020","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1334137","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1334254","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read" "14:59:34.1334372","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1334489","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1334606","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read" "14:59:34.1334724","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1334841","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1334958","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read" "14:59:34.1335076","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1335193","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1335313","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read" "14:59:34.1335430","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1335548","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1335665","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read" "14:59:34.1335782","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1335900","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1336017","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read" "14:59:34.1336134","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1336252","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1336369","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read" "14:59:34.1336486","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1336604","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1336721","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read" "14:59:34.1336838","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1336956","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1337073","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read" "14:59:34.1337190","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1337308","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1337425","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read" "14:59:34.1337542","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1337660","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1337777","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read" "14:59:34.1337894","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1338012","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1338129","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read" "14:59:34.1338246","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1338364","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1338481","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read" "14:59:34.1338598","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1338716","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1338833","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read" "14:59:34.1338950","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1339068","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1339185","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read" "14:59:34.1339302","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1339420","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1339537","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1339654","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read" "14:59:34.1339772","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1339889","RegOpenKey","HKCU\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1340009","RegOpenKey","HKCU\Software\FileZilla Client","NAME NOT FOUND","Desired Access: Read" "14:59:34.1340135","RegOpenKey","HKCU\Software\FileZilla Client","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1340258","RegOpenKey","HKCU\Software\FileZilla Client","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1340372","RegOpenKey","HKLM\Software\FileZilla","NAME NOT FOUND","Desired Access: Read" "14:59:34.1340560","RegOpenKey","HKLM\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1340674","RegOpenKey","HKLM\Software\FileZilla","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1340786","RegOpenKey","HKLM\Software\FileZilla Client","NAME NOT FOUND","Desired Access: Read" "14:59:34.1340962","RegOpenKey","HKLM\Software\FileZilla Client","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1341074","RegOpenKey","HKLM\Software\FileZilla Client","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1354134","RegOpenKey","HKCU\Software\BPFTP\Bullet Proof FTP\Main","NAME NOT FOUND","Desired Access: Read" "14:59:34.1354296","RegOpenKey","HKCU\Software\BPFTP\Bullet Proof FTP\Main","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1354427","RegOpenKey","HKCU\Software\BPFTP\Bullet Proof FTP\Main","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1354567","RegOpenKey","HKCU\Software\BulletProof Software\BulletProof FTP Client\Main","NAME NOT FOUND","Desired Access: Read" "14:59:34.1354715","RegOpenKey","HKCU\Software\BulletProof Software\BulletProof FTP Client\Main","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1354852","RegOpenKey","HKCU\Software\BulletProof Software\BulletProof FTP Client\Main","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1354989","RegOpenKey","HKCU\Software\BPFTP\Bullet Proof FTP\Options","NAME NOT FOUND","Desired Access: Read" "14:59:34.1355117","RegOpenKey","HKCU\Software\BPFTP\Bullet Proof FTP\Options","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1355243","RegOpenKey","HKCU\Software\BPFTP\Bullet Proof FTP\Options","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1355385","RegOpenKey","HKCU\Software\BulletProof Software\BulletProof FTP Client\Options","NAME NOT FOUND","Desired Access: Read" "14:59:34.1355536","RegOpenKey","HKCU\Software\BulletProof Software\BulletProof FTP Client\Options","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1355682","RegOpenKey","HKCU\Software\BulletProof Software\BulletProof FTP Client\Options","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1355816","RegOpenKey","HKCU\Software\BPFTP","NAME NOT FOUND","Desired Access: Read" "14:59:34.1355930","RegOpenKey","HKCU\Software\BPFTP","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1356048","RegOpenKey","HKCU\Software\BPFTP","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1402679","RegOpenKey","HKCU\Software\TurboFTP","NAME NOT FOUND","Desired Access: Read" "14:59:34.1402830","RegOpenKey","HKCU\Software\TurboFTP","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1402956","RegOpenKey","HKCU\Software\TurboFTP","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1403068","RegOpenKey","HKLM\Software\TurboFTP","NAME NOT FOUND","Desired Access: Read" "14:59:34.1403255","RegOpenKey","HKLM\Software\TurboFTP","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1403364","RegOpenKey","HKLM\Software\TurboFTP","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1408454","RegOpenKey","HKCU\Software\TurboFTP","NAME NOT FOUND","Desired Access: Read" "14:59:34.1408588","RegOpenKey","HKCU\Software\TurboFTP","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1408705","RegOpenKey","HKCU\Software\TurboFTP","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1408817","RegOpenKey","HKLM\Software\TurboFTP","NAME NOT FOUND","Desired Access: Read" "14:59:34.1408926","RegOpenKey","HKLM\Software\TurboFTP","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1409032","RegOpenKey","HKLM\Software\TurboFTP","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1414170","RegOpenKey","HKCU\Software\Sota\FFFTP","NAME NOT FOUND","Desired Access: Read" "14:59:34.1414312","RegOpenKey","HKCU\Software\Sota\FFFTP","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1414432","RegOpenKey","HKCU\Software\Sota\FFFTP","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1414552","RegOpenKey","HKCU\Software\Sota\FFFTP","NAME NOT FOUND","Desired Access: Read" "14:59:34.1414670","RegOpenKey","HKCU\Software\Sota\FFFTP","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1414787","RegOpenKey","HKCU\Software\Sota\FFFTP","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1414907","RegOpenKey","HKCU\Software\Sota\FFFTP\Options","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1415117","RegOpenKey","HKCU\Software\CoffeeCup Software\Internet\Profiles","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1415329","RegOpenKey","HKCU\Software\FTPWare\COREFTP\Sites","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1419430","RegOpenKey","HKCU\Software\FTP Explorer\FTP Explorer\Workspace\MFCToolBar-224","NAME NOT FOUND","Desired Access: Read" "14:59:34.1419609","RegOpenKey","HKCU\Software\FTP Explorer\FTP Explorer\Workspace\MFCToolBar-224","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1419754","RegOpenKey","HKCU\Software\FTP Explorer\FTP Explorer\Workspace\MFCToolBar-224","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1419894","RegOpenKey","HKCU\Software\FTP Explorer\Profiles","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1427478","RegOpenKey","HKCU\Software\VanDyke\SecureFX","NAME NOT FOUND","Desired Access: Read" "14:59:34.1427624","RegOpenKey","HKCU\Software\VanDyke\SecureFX","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1427744","RegOpenKey","HKCU\Software\VanDyke\SecureFX","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1435759","RegOpenKey","HKCU\Software\Cryer\WebSitePublisher","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1441070","RegOpenKey","HKCU\Software\ExpanDrive\Sessions","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1441215","RegOpenKey","HKCU\Software\ExpanDrive","NAME NOT FOUND","Desired Access: Read" "14:59:34.1441335","RegOpenKey","HKCU\Software\ExpanDrive","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1441455","RegOpenKey","HKCU\Software\ExpanDrive","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1443972","RegOpenKey","HKLM\Software\NCH Software\ClassicFTP\FTPAccounts","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1444198","RegOpenKey","HKCU\Software\NCH Software\ClassicFTP\FTPAccounts","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1444422","RegOpenKey","HKCU\SOFTWARE\NCH Software\Fling\Accounts","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1444559","RegOpenKey","HKLM\SOFTWARE\NCH Software\Fling\Accounts","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1444768","RegOpenKey","HKCU\Software\FTPClient\Sites","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1444891","RegOpenKey","HKLM\Software\FTPClient\Sites","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1445070","RegOpenKey","HKCU\Software\SoftX.org\FTPClient\Sites","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1445201","RegOpenKey","HKLM\Software\SoftX.org\FTPClient\Sites","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1490889","RegOpenKey","HKCU\SOFTWARE\LeapWare","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1491037","RegOpenKey","HKLM\SOFTWARE\LeapWare","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1491336","RegOpenKey","HKCU\Software\Martin Prikryl","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1491456","RegOpenKey","HKLM\Software\Martin Prikryl","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1499239","RegOpenKey","HKCU\Software\South River Technologies\WebDrive\Connections","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1499409","RegOpenKey","HKLM\Software\South River Technologies\WebDrive\Connections","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1543245","RegOpenKey","HKCU\Software\Opera Software","NAME NOT FOUND","Desired Access: Read" "14:59:34.1543393","RegOpenKey","HKCU\Software\Opera Software","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1543521","RegOpenKey","HKCU\Software\Opera Software","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1543641","RegOpenKey","HKCU\Software\Opera Software","NAME NOT FOUND","Desired Access: Read" "14:59:34.1543761","RegOpenKey","HKCU\Software\Opera Software","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1543882","RegOpenKey","HKCU\Software\Opera Software","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1544183","RegOpenKey","HKCU\Software\Classes\Opera.HTML\shell\open\command","NAME NOT FOUND","Desired Access: Read" "14:59:34.1544298","RegOpenKey","HKCR\Opera.HTML\shell\open\command","NAME NOT FOUND","Desired Access: Read" "14:59:34.1544781","RegOpenKey","HKCU\Software\Classes\Opera.HTML\shell\open\command","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1544876","RegOpenKey","HKCR\Opera.HTML\shell\open\command","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1545141","RegOpenKey","HKCU\Software\Classes\Opera.HTML\shell\open\command","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1545231","RegOpenKey","HKCR\Opera.HTML\shell\open\command","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1550536","RegOpenKey","HKCU\Software\AceBIT","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1550676","RegOpenKey","HKLM\Software\AceBIT","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1550877","RegOpenKey","HKCR\TypeLib\{CB1F2C0F-8094-4AAC-BCF5-41A64E27F777}","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1551148","RegOpenKey","HKCR\TypeLib\{9EA55529-E122-4757-BC79-E4825F80732C}","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1559029","RegOpenKey","HKCU\Software\Mozilla","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1559252","RegOpenKey","HKLM\Software\Mozilla","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1560473","RegOpenKey","HKCU\Software\Mozilla","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1560685","RegOpenKey","HKLM\Software\Mozilla","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1561015","RegOpenKey","HKCU\Software\Mozilla","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1561213","RegOpenKey","HKLM\Software\Mozilla","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1561521","RegOpenKey","HKCU\Software\Mozilla","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1561716","RegOpenKey","HKLM\Software\Mozilla","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1561993","RegOpenKey","HKCU\Software\Mozilla","NAME NOT FOUND","Desired Access: Read" "14:59:34.1562116","RegOpenKey","HKCU\Software\Mozilla","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1562233","RegOpenKey","HKCU\Software\Mozilla","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1562362","RegOpenKey","HKCU\Software\Mozilla","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1562526","RegOpenKey","HKLM\Software\Mozilla","NAME NOT FOUND","Desired Access: Read" "14:59:34.1562633","RegOpenKey","HKLM\Software\Mozilla","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1562739","RegOpenKey","HKLM\Software\Mozilla","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1562853","RegOpenKey","HKLM\Software\Mozilla","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.1563066","RegOpenKey","HKCU\Software\LeechFTP","NAME NOT FOUND","Desired Access: Read" "14:59:34.1563194","RegOpenKey","HKCU\Software\LeechFTP","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1563311","RegOpenKey","HKCU\Software\LeechFTP","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1563429","RegOpenKey","HKCU\Software\LeechFTP","NAME NOT FOUND","Desired Access: Read" "14:59:34.1563543","RegOpenKey","HKCU\Software\LeechFTP","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1563661","RegOpenKey","HKCU\Software\LeechFTP","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1580545","RegOpenKey","HKCU\Software\Classes\CLSID\{11C1D741-A95B-11d2-8A80-0080ADB32FF4}\InProcServer32","NAME NOT FOUND","Desired Access: Read" "14:59:34.1580674","RegOpenKey","HKCR\CLSID\{11C1D741-A95B-11d2-8A80-0080ADB32FF4}\InProcServer32","NAME NOT FOUND","Desired Access: Read" "14:59:34.1581261","RegOpenKey","HKCU\Software\Classes\CLSID\{11C1D741-A95B-11d2-8A80-0080ADB32FF4}\InProcServer32","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1581364","RegOpenKey","HKCR\CLSID\{11C1D741-A95B-11d2-8A80-0080ADB32FF4}\InProcServer32","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:34.1581652","RegOpenKey","HKCU\Software\Classes\CLSID\{11C1D741-A95B-11d2-8A80-0080ADB32FF4}\InProcServer32","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.1581752","RegOpenKey","HKCR\CLSID\{11C1D741-A95B-11d2-8A80-0080ADB32FF4}\InProcServer32","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:34.3017331","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\COMRes.dll","NAME NOT FOUND","Desired Access: Read" "14:59:34.3017692","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CLBCATQ.DLL","NAME NOT FOUND","Desired Access: Read" "14:59:34.3018717","RegOpenKey","HKLM\Software\Microsoft\COM3\Debug","NAME NOT FOUND","Desired Access: All Access" "14:59:34.3018859","RegOpenKey","HKLM\Software\Microsoft\COM3\Debug","NAME NOT FOUND","Desired Access: Read" "14:59:34.3019346","RegQueryValue","HKLM\SOFTWARE\Microsoft\Ole\MinimumFreeMemPercentageToCreateProcess","NAME NOT FOUND","Length: 144" "14:59:34.3019468","RegQueryValue","HKLM\SOFTWARE\Microsoft\Ole\MinimumFreeMemPercentageToCreateObject","NAME NOT FOUND","Length: 144" "14:59:34.3153600","RegOpenKey","HKCU\Software\Classes\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}","NAME NOT FOUND","Desired Access: Read" "14:59:34.3154388","RegOpenKey","HKCU\Software\Classes\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\TreatAs","NAME NOT FOUND","Desired Access: Query Value" "14:59:34.3154583","RegOpenKey","HKCR\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\TreatAs","NAME NOT FOUND","Desired Access: Query Value" "14:59:34.3155366","RegOpenKey","HKCU\Software\Classes\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}","NAME NOT FOUND","Desired Access: Read" "14:59:34.3155874","RegOpenKey","HKCU\Software\Classes\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.3156547","RegOpenKey","HKCU\Software\Classes\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.3156751","RegQueryValue","HKCR\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\InProcServer32\InprocServer32","NAME NOT FOUND","Length: 144" "14:59:34.3157307","RegOpenKey","HKCU\Software\Classes\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\InprocServerX86","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.3157500","RegOpenKey","HKCR\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\InprocServerX86","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.3157816","RegOpenKey","HKCU\Software\Classes\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\LocalServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.3158000","RegOpenKey","HKCR\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\LocalServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.3158313","RegOpenKey","HKCU\Software\Classes\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.3158877","RegOpenKey","HKCU\Software\Classes\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.3159654","RegOpenKey","HKCU\Software\Classes\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\InprocHandler32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.3159841","RegOpenKey","HKCR\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\InprocHandler32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.3160162","RegOpenKey","HKCU\Software\Classes\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\InprocHandlerX86","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.3160350","RegOpenKey","HKCR\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\InprocHandlerX86","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.3160662","RegOpenKey","HKCU\Software\Classes\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\LocalServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.3160841","RegOpenKey","HKCR\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\LocalServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.3161149","RegOpenKey","HKCU\Software\Classes\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\LocalServer","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.3161336","RegOpenKey","HKCR\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\LocalServer","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.3161582","RegOpenKey","HKCU\Software\Classes\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}","NAME NOT FOUND","Desired Access: Read" "14:59:34.3162062","RegOpenKey","HKCU\Software\Classes\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.3162232","RegQueryValue","HKCR\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\AppID","NAME NOT FOUND","Length: 144" "14:59:34.3183160","RegOpenKey","HKCU\Software\Classes\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}","NAME NOT FOUND","Desired Access: Read" "14:59:34.3183878","RegOpenKey","HKCU\Software\Classes\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}","NAME NOT FOUND","Desired Access: Read" "14:59:34.3184394","RegOpenKey","HKCU\Software\Classes\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.3184981","RegOpenKey","HKCU\Software\Classes\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.3186076","RegOpenKey","HKCU\Software\Classes\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}","NAME NOT FOUND","Desired Access: Read" "14:59:34.3186588","RegOpenKey","HKCU\Software\Classes\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\TreatAs","NAME NOT FOUND","Desired Access: Query Value" "14:59:34.3186772","RegOpenKey","HKCR\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\TreatAs","NAME NOT FOUND","Desired Access: Query Value" "14:59:34.3705092","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read" "14:59:34.3705464","RegQueryValue","HKCU\Control Panel\Desktop\MultiUILanguageId","NAME NOT FOUND","Length: 256" "14:59:34.8667597","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IMAGEHLP.dll","NAME NOT FOUND","Desired Access: Read" "14:59:34.8669125","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WINTRUST.dll","NAME NOT FOUND","Desired Access: Read" "14:59:34.8670055","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WLDAP32.dll","NAME NOT FOUND","Desired Access: Read" "14:59:34.8671913","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CRYPTUI.dll","NAME NOT FOUND","Desired Access: Read" "14:59:34.8673047","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots","NAME NOT FOUND","Desired Access: Enumerate Sub Keys" "14:59:34.8845435","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RichEd20.dll","NAME NOT FOUND","Desired Access: Read" "14:59:34.8996611","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shdocvw.dll","NAME NOT FOUND","Desired Access: Read" "14:59:34.9098699","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read" "14:59:34.9099266","RegQueryValue","HKCU\Control Panel\Desktop\MultiUILanguageId","NAME NOT FOUND","Length: 256" "14:59:34.9646917","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots","NAME NOT FOUND","Desired Access: Enumerate Sub Keys" "14:59:34.9693015","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Performance","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.9694638","RegOpenKey","HKCU\Software\Classes\clsid\{c90250f3-4d7d-4991-9b69-a5c5bc1c2ae6}","NAME NOT FOUND","Desired Access: Query Value" "14:59:34.9694842","RegOpenKey","HKCR\clsid\{c90250f3-4d7d-4991-9b69-a5c5bc1c2ae6}","NAME NOT FOUND","Desired Access: Query Value" "14:59:34.9695387","RegOpenKey","HKCU\Software\Classes\Interface\{EAB22AC1-30C1-11CF-A7EB-0000C05BAE0B}\Typelib","NAME NOT FOUND","Desired Access: Query Value" "14:59:34.9696462","RegOpenKey","HKCU\Software\Classes\Interface\{EAB22AC1-30C1-11CF-A7EB-0000C05BAE0B}\TypeLib","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.9698007","RegOpenKey","HKCU\Software\Classes\Interface\{b722bccb-4e68-101b-a2bc-00aa00404770}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Query Value" "14:59:34.9699021","RegOpenKey","HKCU\Software\Classes\Interface\{B722BCCB-4E68-101B-A2BC-00AA00404770}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.9700197","RegOpenKey","HKCU\Software\Classes\Interface\{79eac9c4-baf9-11ce-8c82-00aa004ba90b}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Query Value" "14:59:34.9701164","RegOpenKey","HKCU\Software\Classes\Interface\{79EAC9C4-BAF9-11CE-8C82-00AA004BA90B}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.9702309","RegOpenKey","HKCU\Software\Classes\Interface\{000214E6-0000-0000-C000-000000000046}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Query Value" "14:59:34.9703259","RegOpenKey","HKCU\Software\Classes\Interface\{000214E6-0000-0000-C000-000000000046}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.9704399","RegOpenKey","HKCU\Software\Classes\Interface\{93F2F68C-1D1B-11D3-A30E-00C04F79ABD1}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Query Value" "14:59:34.9705341","RegOpenKey","HKCU\Software\Classes\Interface\{93F2F68C-1D1B-11D3-A30E-00C04F79ABD1}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:34.9729006","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5","NAME NOT FOUND","Length: 144" "14:59:34.9729782","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\FixupKey","NAME NOT FOUND","Length: 144" "14:59:34.9730791","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs","NAME NOT FOUND","Length: 144" "14:59:34.9749086","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem","NAME NOT FOUND","Length: 144" "14:59:34.9924963","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem","NAME NOT FOUND","Length: 144" "14:59:34.9947871","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem","NAME NOT FOUND","Length: 144" "14:59:35.1791086","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012013052720130603\CachePath","BUFFER OVERFLOW","Length: 144" "14:59:35.1791678","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012013052720130603\CachePath","BUFFER OVERFLOW","Length: 144" "14:59:35.1795215","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012013060420130605\CachePath","BUFFER OVERFLOW","Length: 144" "14:59:35.1795768","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012013060420130605\CachePath","BUFFER OVERFLOW","Length: 144" "14:59:35.1841629","RegEnumKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache","NO MORE ENTRIES","Index: 2, Length: 288" "14:59:35.1856217","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.1856737","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.1857011","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.1861226","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.1861514","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.1861774","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.1869577","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.1869864","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.1870121","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.1874200","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.1874482","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.1874736","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.1878740","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.1879022","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.1879276","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.1883196","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.1883475","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.1883726","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.1887674","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.1887953","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.1888205","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.1892188","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.1892471","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.1892725","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.1896714","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.1896996","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.1897250","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.1901223","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.1901500","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.1901754","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.1905841","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.1906123","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.1906377","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.1910355","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.1910635","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.1910886","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.1914792","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.1915074","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.1915328","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.1919373","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.1919653","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.1919904","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.1923907","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.1924187","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.1924441","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.1928355","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.1928634","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.1928886","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.1935845","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.1936135","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.1936395","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.1945332","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.1945617","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.1945871","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.1949824","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.1950104","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.1950355","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.1954476","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.1954755","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.1955006","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.1958999","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.1959278","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.1959529","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.1963513","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.1963792","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.1964044","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.2112250","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.2112588","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.2112850","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.2116904","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read" "14:59:35.2117189","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.2117449","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IntelliForms\Storage2","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.2383980","RegOpenKey","HKCU\Software\Adobe\Common","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.2429148","RegOpenKey","HKCU\Software\ChromePlus","NAME NOT FOUND","Desired Access: Read" "14:59:35.2429396","RegOpenKey","HKCU\Software\ChromePlus","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.2429603","RegOpenKey","HKCU\Software\ChromePlus","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.2616699","RegOpenKey","HKCU\Software\FlashPeak\BlazeFtp\Settings","NAME NOT FOUND","Desired Access: Read" "14:59:35.2616987","RegOpenKey","HKCU\Software\FlashPeak\BlazeFtp\Settings","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.2617208","RegOpenKey","HKCU\Software\FlashPeak\BlazeFtp\Settings","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.2617420","RegOpenKey","HKCU\Software\FlashPeak\BlazeFtp\Settings","NAME NOT FOUND","Desired Access: Read" "14:59:35.2617633","RegOpenKey","HKCU\Software\FlashPeak\BlazeFtp\Settings","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.2617848","RegOpenKey","HKCU\Software\FlashPeak\BlazeFtp\Settings","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.2618063","RegOpenKey","HKCU\Software\FlashPeak\BlazeFtp\Settings","NAME NOT FOUND","Desired Access: Read" "14:59:35.2618272","RegOpenKey","HKCU\Software\FlashPeak\BlazeFtp\Settings","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.2618485","RegOpenKey","HKCU\Software\FlashPeak\BlazeFtp\Settings","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.2618697","RegOpenKey","HKCU\Software\FlashPeak\BlazeFtp\Settings","NAME NOT FOUND","Desired Access: Read" "14:59:35.2618906","RegOpenKey","HKCU\Software\FlashPeak\BlazeFtp\Settings","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.2619116","RegOpenKey","HKCU\Software\FlashPeak\BlazeFtp\Settings","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.2619784","RegOpenKey","HKCU\Software\Classes\FTP++.Link\shell\open\command","NAME NOT FOUND","Desired Access: Read" "14:59:35.2619968","RegOpenKey","HKCR\FTP++.Link\shell\open\command","NAME NOT FOUND","Desired Access: Read" "14:59:35.2620750","RegOpenKey","HKCU\Software\Classes\FTP++.Link\shell\open\command","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.2620901","RegOpenKey","HKCR\FTP++.Link\shell\open\command","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.2621356","RegOpenKey","HKCU\Software\Classes\FTP++.Link\shell\open\command","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.2621499","RegOpenKey","HKCR\FTP++.Link\shell\open\command","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.2642278","RegOpenKey","HKCR\TypeLib\{F9043C88-F6F2-101A-A3C9-08002B2F49FB}\1.2\0\win32","NAME NOT FOUND","Desired Access: Read" "14:59:35.2642742","RegOpenKey","HKCR\TypeLib\{F9043C88-F6F2-101A-A3C9-08002B2F49FB}\1.2\0\win32","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.2643002","RegOpenKey","HKCR\TypeLib\{F9043C88-F6F2-101A-A3C9-08002B2F49FB}\1.2\0\win32","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.2997726","RegOpenKey","HKCU\SOFTWARE\Robo-FTP 3.7\FTPServers","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.2998005","RegOpenKey","HKLM\SOFTWARE\Robo-FTP 3.7\FTPServers","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.2998410","RegOpenKey","HKCU\SOFTWARE\Robo-FTP 3.7\Scripts","NAME NOT FOUND","Desired Access: Read" "14:59:35.2998628","RegOpenKey","HKCU\SOFTWARE\Robo-FTP 3.7\Scripts","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.2998835","RegOpenKey","HKCU\SOFTWARE\Robo-FTP 3.7\Scripts","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.2999030","RegOpenKey","HKLM\SOFTWARE\Robo-FTP 3.7\Scripts","NAME NOT FOUND","Desired Access: Read" "14:59:35.2999231","RegOpenKey","HKLM\SOFTWARE\Robo-FTP 3.7\Scripts","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.2999424","RegOpenKey","HKLM\SOFTWARE\Robo-FTP 3.7\Scripts","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.3007850","RegEnumKey","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv","NO MORE ENTRIES","Index: 2, Length: 288" "14:59:35.3009252","RegOpenKey","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CertDllOpenStoreProv","NAME NOT FOUND","Desired Access: Read" "14:59:35.3009802","RegEnumKey","HKLM\SOFTWARE\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "14:59:35.3180087","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\MY\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "14:59:35.3282882","RegEnumValue","HKCU\Environment","NO MORE ENTRIES","Index: 2, Length: 220" "14:59:35.3352380","RegEnumValue","HKCU\Environment","NO MORE ENTRIES","Index: 2, Length: 220" "14:59:35.3356810","RegEnumValue","HKCU\Volatile Environment","NO MORE ENTRIES","Index: 7, Length: 220" "14:59:35.3358093","RegEnumValue","HKCU\Volatile Environment","NO MORE ENTRIES","Index: 7, Length: 220" "14:59:35.3361096","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\My\Certificates","NAME NOT FOUND","Desired Access: All Access" "14:59:35.3544943","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\My\CRLs","NAME NOT FOUND","Desired Access: All Access" "14:59:35.3562311","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\My\CTLs","NAME NOT FOUND","Desired Access: All Access" "14:59:35.3579327","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\My\Keys","NAME NOT FOUND","Desired Access: All Access" "14:59:35.3581126","RegOpenKey","HKCU\Software\LinasFTP\Site Manager","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.3597841","RegOpenKey","HKCU\Software\SimonTatham\PuTTY\Sessions","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.3598120","RegOpenKey","HKLM\Software\SimonTatham\PuTTY\Sessions","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.3605236","RegOpenKey","HKCU\Software\CoffeeCup Software","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.3605476","RegOpenKey","HKLM\Software\CoffeeCup Software","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.3611155","RegOpenKey","HKCU\Software\MAS-Soft\FTPInfo\Setup","NAME NOT FOUND","Desired Access: Read" "14:59:35.3611404","RegOpenKey","HKCU\Software\MAS-Soft\FTPInfo\Setup","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.3611616","RegOpenKey","HKCU\Software\MAS-Soft\FTPInfo\Setup","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.3638793","RegOpenKey","HKCU\Software\Nico Mak Computing\WinZip\FTP","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.3639050","RegOpenKey","HKLM\Software\Nico Mak Computing\WinZip\FTP","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.3639399","RegOpenKey","HKCU\Software\Nico Mak Computing\WinZip\mru\jobs","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.3639631","RegOpenKey","HKLM\Software\Nico Mak Computing\WinZip\mru\jobs","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.4178052","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer\DisableUserInstalls","NAME NOT FOUND","Length: 144" "14:59:35.4178700","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer\Debug","NAME NOT FOUND","Length: 144" "14:59:35.4180091","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1214440339-926492609-1644491937-1003\Installer\Products\0371FF472F1B88D429B65186AF6ED17B","NAME NOT FOUND","Desired Access: Read" "14:59:35.4181016","RegOpenKey","HKCU\Software\Microsoft\Installer\Products\0371FF472F1B88D429B65186AF6ED17B","NAME NOT FOUND","Desired Access: Read" "14:59:35.4181463","RegOpenKey","HKCR\Installer\Products\0371FF472F1B88D429B65186AF6ED17B","NAME NOT FOUND","Desired Access: Read" "14:59:35.4182591","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1214440339-926492609-1644491937-1003\Installer\Products\0371FF472F1B88D429B65186AF6ED17B","NAME NOT FOUND","Desired Access: Read" "14:59:35.4183264","RegOpenKey","HKCU\Software\Microsoft\Installer\Products\0371FF472F1B88D429B65186AF6ED17B","NAME NOT FOUND","Desired Access: Read" "14:59:35.4183619","RegOpenKey","HKCR\Installer\Products\0371FF472F1B88D429B65186AF6ED17B","NAME NOT FOUND","Desired Access: Read" "14:59:35.4321598","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1214440339-926492609-1644491937-1003\Installer\Products\0371FF472F1B88D429B65186AF6ED17B","NAME NOT FOUND","Desired Access: Read" "14:59:35.4322296","RegOpenKey","HKCU\Software\Microsoft\Installer\Products\0371FF472F1B88D429B65186AF6ED17B","NAME NOT FOUND","Desired Access: Read" "14:59:35.4322662","RegOpenKey","HKCR\Installer\Products\0371FF472F1B88D429B65186AF6ED17B","NAME NOT FOUND","Desired Access: Read" "14:59:35.4323327","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1214440339-926492609-1644491937-1003\Installer\Products\0371FF472F1B88D429B65186AF6ED17B","NAME NOT FOUND","Desired Access: Read" "14:59:35.4323975","RegOpenKey","HKCU\Software\Microsoft\Installer\Products\0371FF472F1B88D429B65186AF6ED17B","NAME NOT FOUND","Desired Access: Read" "14:59:35.4324327","RegOpenKey","HKCR\Installer\Products\0371FF472F1B88D429B65186AF6ED17B","NAME NOT FOUND","Desired Access: Read" "14:59:35.4326014","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0371FF472F1B88D429B65186AF6ED17B\InstallProperties","NAME NOT FOUND","Desired Access: Read" "14:59:35.4327783","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1214440339-926492609-1644491937-1003\Products\0371FF472F1B88D429B65186AF6ED17B\InstallProperties","NAME NOT FOUND","Desired Access: Read" "14:59:35.4328814","RegEnumKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData","NO MORE ENTRIES","Index: 2, Length: 288" "14:59:35.4329783","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1214440339-926492609-1644491937-1003\Components\0371FF472F1B88D429B65186AF6ED17B","NAME NOT FOUND","Desired Access: Read" "14:59:35.4330504","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0371FF472F1B88D429B65186AF6ED17B","NAME NOT FOUND","Desired Access: Read" "14:59:35.4369682","RegOpenKey","HKCU\Software\Microsoft\Windows Live Mail","NAME NOT FOUND","Desired Access: Read" "14:59:35.4370216","RegOpenKey","HKCU\Software\Microsoft\Windows Live Mail","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.4370450","RegOpenKey","HKCU\Software\Microsoft\Windows Live Mail","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.4370819","RegOpenKey","HKCU\Software\Microsoft\Windows Mail","NAME NOT FOUND","Desired Access: Read" "14:59:35.4371227","RegOpenKey","HKCU\Software\Microsoft\Windows Mail","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.4371439","RegOpenKey","HKCU\Software\Microsoft\Windows Mail","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.4371788","RegOpenKey","HKCU\Software\RimArts\B2\Settings","NAME NOT FOUND","Desired Access: Read" "14:59:35.4372017","RegOpenKey","HKCU\Software\RimArts\B2\Settings","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.4372224","RegOpenKey","HKCU\Software\RimArts\B2\Settings","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.4372425","RegOpenKey","HKLM\Software\RimArts\B2\Settings","NAME NOT FOUND","Desired Access: Read" "14:59:35.4372747","RegOpenKey","HKLM\Software\RimArts\B2\Settings","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.4372942","RegOpenKey","HKLM\Software\RimArts\B2\Settings","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.4373152","RegOpenKey","HKCU\Software\RimArts\B2\Settings","NAME NOT FOUND","Desired Access: Read" "14:59:35.4373356","RegOpenKey","HKCU\Software\RimArts\B2\Settings","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.4373560","RegOpenKey","HKCU\Software\RimArts\B2\Settings","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.4373755","RegOpenKey","HKLM\Software\RimArts\B2\Settings","NAME NOT FOUND","Desired Access: Read" "14:59:35.4373942","RegOpenKey","HKLM\Software\RimArts\B2\Settings","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.4374129","RegOpenKey","HKLM\Software\RimArts\B2\Settings","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.4374487","RegOpenKey","HKCU\Software\Poco Systems Inc","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.4374702","RegOpenKey","HKLM\Software\Poco Systems Inc","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.4383891","RegOpenKey","HKCU\Software\IncrediMail","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.4384128","RegOpenKey","HKLM\Software\IncrediMail","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.4420901","RegOpenKey","HKCU\Software\RIT\The Bat!","NAME NOT FOUND","Desired Access: Read" "14:59:35.4421158","RegOpenKey","HKCU\Software\RIT\The Bat!","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.4421367","RegOpenKey","HKCU\Software\RIT\The Bat!","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.4421568","RegOpenKey","HKCU\Software\RIT\The Bat!","NAME NOT FOUND","Desired Access: Read" "14:59:35.4421764","RegOpenKey","HKCU\Software\RIT\The Bat!","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.4421960","RegOpenKey","HKCU\Software\RIT\The Bat!","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.4422164","RegOpenKey","HKCU\Software\RIT\The Bat!\Users depot","NAME NOT FOUND","Desired Access: Read" "14:59:35.4422379","RegOpenKey","HKCU\Software\RIT\The Bat!\Users depot","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.4422588","RegOpenKey","HKCU\Software\RIT\The Bat!\Users depot","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.4422800","RegOpenKey","HKCU\Software\RIT\The Bat!\Users depot","NAME NOT FOUND","Desired Access: Read" "14:59:35.4423007","RegOpenKey","HKCU\Software\RIT\The Bat!\Users depot","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.4423214","RegOpenKey","HKCU\Software\RIT\The Bat!\Users depot","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.4423412","RegOpenKey","HKLM\Software\RIT\The Bat!","NAME NOT FOUND","Desired Access: Read" "14:59:35.4423706","RegOpenKey","HKLM\Software\RIT\The Bat!","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.4423890","RegOpenKey","HKLM\Software\RIT\The Bat!","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.4424069","RegOpenKey","HKLM\Software\RIT\The Bat!","NAME NOT FOUND","Desired Access: Read" "14:59:35.4424248","RegOpenKey","HKLM\Software\RIT\The Bat!","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.4424426","RegOpenKey","HKLM\Software\RIT\The Bat!","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.4424611","RegOpenKey","HKLM\Software\RIT\The Bat!\Users depot","NAME NOT FOUND","Desired Access: Read" "14:59:35.4424812","RegOpenKey","HKLM\Software\RIT\The Bat!\Users depot","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.4425005","RegOpenKey","HKLM\Software\RIT\The Bat!\Users depot","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.4425195","RegOpenKey","HKLM\Software\RIT\The Bat!\Users depot","NAME NOT FOUND","Desired Access: Read" "14:59:35.4425385","RegOpenKey","HKLM\Software\RIT\The Bat!\Users depot","NAME NOT FOUND","Desired Access: Read, WOW64_32Key" "14:59:35.4425575","RegOpenKey","HKLM\Software\RIT\The Bat!\Users depot","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:35.4611727","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\SMTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.4612730","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\SMTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.4613674","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\SMTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.4614621","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\SMTP Server","NAME NOT FOUND","Length: 144" "14:59:35.4615551","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\SMTP Server","NAME NOT FOUND","Length: 144" "14:59:35.4616479","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\SMTP Server","NAME NOT FOUND","Length: 144" "14:59:35.4617412","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\POP3 Server","NAME NOT FOUND","Length: 144" "14:59:35.4618345","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\POP3 Server","NAME NOT FOUND","Length: 144" "14:59:35.4619270","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\POP3 Server","NAME NOT FOUND","Length: 144" "14:59:35.4620214","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\POP3 User Name","NAME NOT FOUND","Length: 144" "14:59:35.4621139","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\POP3 User Name","NAME NOT FOUND","Length: 144" "14:59:35.4622066","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\POP3 User Name","NAME NOT FOUND","Length: 144" "14:59:35.4622994","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\SMTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4623924","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\SMTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4624849","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\SMTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4625787","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\NNTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.4626715","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\NNTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.4627642","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\NNTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.4628572","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\NNTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4629497","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\NNTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4630416","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\NNTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4631344","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\NNTP Server","NAME NOT FOUND","Length: 144" "14:59:35.4632266","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\NNTP Server","NAME NOT FOUND","Length: 144" "14:59:35.4633188","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\NNTP Server","NAME NOT FOUND","Length: 144" "14:59:35.4634118","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\IMAP Server","NAME NOT FOUND","Length: 144" "14:59:35.4635040","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\IMAP Server","NAME NOT FOUND","Length: 144" "14:59:35.4635964","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\IMAP Server","NAME NOT FOUND","Length: 144" "14:59:35.4636895","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\IMAP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4637822","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\IMAP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4638744","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\IMAP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4639677","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\Email","NAME NOT FOUND","Length: 144" "14:59:35.4640602","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\Email","NAME NOT FOUND","Length: 144" "14:59:35.4641524","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\Email","NAME NOT FOUND","Length: 144" "14:59:35.4642454","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\HTTP User","NAME NOT FOUND","Length: 144" "14:59:35.4643373","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\HTTP User","NAME NOT FOUND","Length: 144" "14:59:35.4644292","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\HTTP User","NAME NOT FOUND","Length: 144" "14:59:35.4645220","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\HTTP Server URL","NAME NOT FOUND","Length: 144" "14:59:35.4646142","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\HTTP Server URL","NAME NOT FOUND","Length: 144" "14:59:35.4647161","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\HTTP Server URL","NAME NOT FOUND","Length: 144" "14:59:35.4684337","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\POP3 User","NAME NOT FOUND","Length: 144" "14:59:35.4685334","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\POP3 User","NAME NOT FOUND","Length: 144" "14:59:35.4686273","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\POP3 User","NAME NOT FOUND","Length: 144" "14:59:35.4687208","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\IMAP User","NAME NOT FOUND","Length: 144" "14:59:35.4688139","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\IMAP User","NAME NOT FOUND","Length: 144" "14:59:35.4689063","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\IMAP User","NAME NOT FOUND","Length: 144" "14:59:35.4690008","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\HTTPMail User Name","NAME NOT FOUND","Length: 144" "14:59:35.4690935","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\HTTPMail User Name","NAME NOT FOUND","Length: 144" "14:59:35.4691865","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\HTTPMail User Name","NAME NOT FOUND","Length: 144" "14:59:35.4692807","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\HTTPMail Server","NAME NOT FOUND","Length: 144" "14:59:35.4693734","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\HTTPMail Server","NAME NOT FOUND","Length: 144" "14:59:35.4694667","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\HTTPMail Server","NAME NOT FOUND","Length: 144" "14:59:35.4695609","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\SMTP User","NAME NOT FOUND","Length: 144" "14:59:35.4696539","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\SMTP User","NAME NOT FOUND","Length: 144" "14:59:35.4697464","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\SMTP User","NAME NOT FOUND","Length: 144" "14:59:35.4698397","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\POP3 Password2","NAME NOT FOUND","Length: 144" "14:59:35.4699324","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\POP3 Password2","NAME NOT FOUND","Length: 144" "14:59:35.4700255","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\POP3 Password2","NAME NOT FOUND","Length: 144" "14:59:35.4701191","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\IMAP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4702118","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\IMAP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4703046","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\IMAP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4703979","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\NNTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4704903","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\NNTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4705831","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\NNTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4706767","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\HTTPMail Password2","NAME NOT FOUND","Length: 144" "14:59:35.4707697","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\HTTPMail Password2","NAME NOT FOUND","Length: 144" "14:59:35.4708630","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\HTTPMail Password2","NAME NOT FOUND","Length: 144" "14:59:35.4709566","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\SMTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4710493","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\SMTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4711424","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\SMTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4712362","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\POP3 Password","NAME NOT FOUND","Length: 144" "14:59:35.4713296","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\POP3 Password","NAME NOT FOUND","Length: 144" "14:59:35.4714223","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\POP3 Password","NAME NOT FOUND","Length: 144" "14:59:35.4715156","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\IMAP Password","NAME NOT FOUND","Length: 144" "14:59:35.4716089","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\IMAP Password","NAME NOT FOUND","Length: 144" "14:59:35.4717017","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\IMAP Password","NAME NOT FOUND","Length: 144" "14:59:35.4717950","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\NNTP Password","NAME NOT FOUND","Length: 144" "14:59:35.4718880","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\NNTP Password","NAME NOT FOUND","Length: 144" "14:59:35.4719808","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\NNTP Password","NAME NOT FOUND","Length: 144" "14:59:35.4720741","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\HTTP Password","NAME NOT FOUND","Length: 144" "14:59:35.4721665","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\HTTP Password","NAME NOT FOUND","Length: 144" "14:59:35.4722596","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\HTTP Password","NAME NOT FOUND","Length: 144" "14:59:35.4723526","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\SMTP Password","NAME NOT FOUND","Length: 144" "14:59:35.4724459","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\SMTP Password","NAME NOT FOUND","Length: 144" "14:59:35.4725384","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\SMTP Password","NAME NOT FOUND","Length: 144" "14:59:35.4726317","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\POP3 Port","NAME NOT FOUND","Length: 144" "14:59:35.4727241","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\POP3 Port","NAME NOT FOUND","Length: 144" "14:59:35.4728169","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\POP3 Port","NAME NOT FOUND","Length: 144" "14:59:35.4729105","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\SMTP Port","NAME NOT FOUND","Length: 144" "14:59:35.4730063","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\SMTP Port","NAME NOT FOUND","Length: 144" "14:59:35.4730990","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\SMTP Port","NAME NOT FOUND","Length: 144" "14:59:35.4731918","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\IMAP Port","NAME NOT FOUND","Length: 144" "14:59:35.4732848","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\IMAP Port","NAME NOT FOUND","Length: 144" "14:59:35.4733779","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC\IMAP Port","NAME NOT FOUND","Length: 144" "14:59:35.4774580","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\SMTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.4775549","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\SMTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.4776452","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\SMTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.4777351","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\SMTP Server","NAME NOT FOUND","Length: 144" "14:59:35.4778248","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\SMTP Server","NAME NOT FOUND","Length: 144" "14:59:35.4779145","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\SMTP Server","NAME NOT FOUND","Length: 144" "14:59:35.4780047","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\POP3 Server","NAME NOT FOUND","Length: 144" "14:59:35.4780944","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\POP3 Server","NAME NOT FOUND","Length: 144" "14:59:35.4781843","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\POP3 Server","NAME NOT FOUND","Length: 144" "14:59:35.4782746","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\POP3 User Name","NAME NOT FOUND","Length: 144" "14:59:35.4783645","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\POP3 User Name","NAME NOT FOUND","Length: 144" "14:59:35.4784545","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\POP3 User Name","NAME NOT FOUND","Length: 144" "14:59:35.4788964","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\SMTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4789914","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\SMTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4790817","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\SMTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4791724","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\NNTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.4792632","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\NNTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.4793532","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\NNTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.4794432","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\NNTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4795328","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\NNTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4796225","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\NNTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4797125","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\NNTP Server","NAME NOT FOUND","Length: 144" "14:59:35.4798021","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\NNTP Server","NAME NOT FOUND","Length: 144" "14:59:35.4798913","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\NNTP Server","NAME NOT FOUND","Length: 144" "14:59:35.4799812","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\IMAP Server","NAME NOT FOUND","Length: 144" "14:59:35.4800709","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\IMAP Server","NAME NOT FOUND","Length: 144" "14:59:35.4801603","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\IMAP Server","NAME NOT FOUND","Length: 144" "14:59:35.4802502","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\IMAP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4803396","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\IMAP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4804288","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\IMAP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4805184","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\Email","NAME NOT FOUND","Length: 144" "14:59:35.4806075","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\Email","NAME NOT FOUND","Length: 144" "14:59:35.4806964","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\Email","NAME NOT FOUND","Length: 144" "14:59:35.4807852","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\HTTP User","NAME NOT FOUND","Length: 144" "14:59:35.4808746","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\HTTP User","NAME NOT FOUND","Length: 144" "14:59:35.4809635","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\HTTP User","NAME NOT FOUND","Length: 144" "14:59:35.4810540","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\HTTP Server URL","NAME NOT FOUND","Length: 144" "14:59:35.4811434","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\HTTP Server URL","NAME NOT FOUND","Length: 144" "14:59:35.4812328","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\HTTP Server URL","NAME NOT FOUND","Length: 144" "14:59:35.4813227","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\POP3 User","NAME NOT FOUND","Length: 144" "14:59:35.4814124","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\POP3 User","NAME NOT FOUND","Length: 144" "14:59:35.4815015","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\POP3 User","NAME NOT FOUND","Length: 144" "14:59:35.4815917","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\IMAP User","NAME NOT FOUND","Length: 144" "14:59:35.4816814","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\IMAP User","NAME NOT FOUND","Length: 144" "14:59:35.4817705","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\IMAP User","NAME NOT FOUND","Length: 144" "14:59:35.4818602","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\HTTPMail User Name","NAME NOT FOUND","Length: 144" "14:59:35.4819496","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\HTTPMail User Name","NAME NOT FOUND","Length: 144" "14:59:35.4820390","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\HTTPMail User Name","NAME NOT FOUND","Length: 144" "14:59:35.4821292","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\HTTPMail Server","NAME NOT FOUND","Length: 144" "14:59:35.4822189","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\HTTPMail Server","NAME NOT FOUND","Length: 144" "14:59:35.4823083","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\HTTPMail Server","NAME NOT FOUND","Length: 144" "14:59:35.4824000","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\SMTP User","NAME NOT FOUND","Length: 144" "14:59:35.4824893","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\SMTP User","NAME NOT FOUND","Length: 144" "14:59:35.4825782","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\SMTP User","NAME NOT FOUND","Length: 144" "14:59:35.4826768","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\POP3 Password2","NAME NOT FOUND","Length: 144" "14:59:35.4827665","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\POP3 Password2","NAME NOT FOUND","Length: 144" "14:59:35.4828550","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\POP3 Password2","NAME NOT FOUND","Length: 144" "14:59:35.4829447","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\IMAP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4830338","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\IMAP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4831227","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\IMAP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4834006","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\NNTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4834925","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\NNTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4835814","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\NNTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4836713","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\HTTPMail Password2","NAME NOT FOUND","Length: 144" "14:59:35.4837610","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\HTTPMail Password2","NAME NOT FOUND","Length: 144" "14:59:35.4838507","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\HTTPMail Password2","NAME NOT FOUND","Length: 144" "14:59:35.4872034","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\SMTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4872961","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\SMTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4873861","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\SMTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4874763","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\POP3 Password","NAME NOT FOUND","Length: 144" "14:59:35.4875663","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\POP3 Password","NAME NOT FOUND","Length: 144" "14:59:35.4876559","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\POP3 Password","NAME NOT FOUND","Length: 144" "14:59:35.4877459","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\IMAP Password","NAME NOT FOUND","Length: 144" "14:59:35.4878350","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\IMAP Password","NAME NOT FOUND","Length: 144" "14:59:35.4879247","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\IMAP Password","NAME NOT FOUND","Length: 144" "14:59:35.4880144","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\NNTP Password","NAME NOT FOUND","Length: 144" "14:59:35.4881093","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\NNTP Password","NAME NOT FOUND","Length: 144" "14:59:35.4881990","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\NNTP Password","NAME NOT FOUND","Length: 144" "14:59:35.4882895","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\HTTP Password","NAME NOT FOUND","Length: 144" "14:59:35.4883786","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\HTTP Password","NAME NOT FOUND","Length: 144" "14:59:35.4884678","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\HTTP Password","NAME NOT FOUND","Length: 144" "14:59:35.4885574","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\SMTP Password","NAME NOT FOUND","Length: 144" "14:59:35.4886468","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\SMTP Password","NAME NOT FOUND","Length: 144" "14:59:35.4887360","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\SMTP Password","NAME NOT FOUND","Length: 144" "14:59:35.4888262","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\POP3 Port","NAME NOT FOUND","Length: 144" "14:59:35.4889161","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\POP3 Port","NAME NOT FOUND","Length: 144" "14:59:35.4890053","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\POP3 Port","NAME NOT FOUND","Length: 144" "14:59:35.4890947","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\SMTP Port","NAME NOT FOUND","Length: 144" "14:59:35.4891835","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\SMTP Port","NAME NOT FOUND","Length: 144" "14:59:35.4892726","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\SMTP Port","NAME NOT FOUND","Length: 144" "14:59:35.4893626","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\IMAP Port","NAME NOT FOUND","Length: 144" "14:59:35.4897892","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\IMAP Port","NAME NOT FOUND","Length: 144" "14:59:35.4898830","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot\IMAP Port","NAME NOT FOUND","Length: 144" "14:59:35.4900085","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\SMTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.4901018","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\SMTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.4901920","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\SMTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.4902831","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\SMTP Server","NAME NOT FOUND","Length: 144" "14:59:35.4903730","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\SMTP Server","NAME NOT FOUND","Length: 144" "14:59:35.4904627","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\SMTP Server","NAME NOT FOUND","Length: 144" "14:59:35.4905529","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\POP3 Server","NAME NOT FOUND","Length: 144" "14:59:35.4907479","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\POP3 Server","NAME NOT FOUND","Length: 144" "14:59:35.4908426","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\POP3 Server","NAME NOT FOUND","Length: 144" "14:59:35.4909334","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\POP3 User Name","NAME NOT FOUND","Length: 144" "14:59:35.4910231","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\POP3 User Name","NAME NOT FOUND","Length: 144" "14:59:35.4911128","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\POP3 User Name","NAME NOT FOUND","Length: 144" "14:59:35.4912058","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\SMTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4946174","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\SMTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4947110","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\SMTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4948021","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\NNTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.4948923","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\NNTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.4949826","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\NNTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.4950728","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\NNTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4951636","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\NNTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4952538","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\NNTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4953441","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\NNTP Server","NAME NOT FOUND","Length: 144" "14:59:35.4954343","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\NNTP Server","NAME NOT FOUND","Length: 144" "14:59:35.4955242","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\NNTP Server","NAME NOT FOUND","Length: 144" "14:59:35.4956145","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\IMAP Server","NAME NOT FOUND","Length: 144" "14:59:35.4957044","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\IMAP Server","NAME NOT FOUND","Length: 144" "14:59:35.4957941","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\IMAP Server","NAME NOT FOUND","Length: 144" "14:59:35.4958852","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\IMAP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4959754","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\IMAP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4960657","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\IMAP User Name","NAME NOT FOUND","Length: 144" "14:59:35.4961556","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\Email","NAME NOT FOUND","Length: 144" "14:59:35.4962450","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\Email","NAME NOT FOUND","Length: 144" "14:59:35.4963344","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\Email","NAME NOT FOUND","Length: 144" "14:59:35.4964244","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\HTTP User","NAME NOT FOUND","Length: 144" "14:59:35.4965146","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\HTTP User","NAME NOT FOUND","Length: 144" "14:59:35.4966046","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\HTTP User","NAME NOT FOUND","Length: 144" "14:59:35.4966945","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\HTTP Server URL","NAME NOT FOUND","Length: 144" "14:59:35.4967845","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\HTTP Server URL","NAME NOT FOUND","Length: 144" "14:59:35.4968747","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\HTTP Server URL","NAME NOT FOUND","Length: 144" "14:59:35.4969652","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\POP3 User","NAME NOT FOUND","Length: 144" "14:59:35.4970546","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\POP3 User","NAME NOT FOUND","Length: 144" "14:59:35.4971446","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\POP3 User","NAME NOT FOUND","Length: 144" "14:59:35.4972348","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\IMAP User","NAME NOT FOUND","Length: 144" "14:59:35.4973248","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\IMAP User","NAME NOT FOUND","Length: 144" "14:59:35.4974147","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\IMAP User","NAME NOT FOUND","Length: 144" "14:59:35.4975052","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\HTTPMail User Name","NAME NOT FOUND","Length: 144" "14:59:35.4975952","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\HTTPMail User Name","NAME NOT FOUND","Length: 144" "14:59:35.4976851","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\HTTPMail User Name","NAME NOT FOUND","Length: 144" "14:59:35.4977759","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\HTTPMail Server","NAME NOT FOUND","Length: 144" "14:59:35.4978664","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\HTTPMail Server","NAME NOT FOUND","Length: 144" "14:59:35.4979567","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\HTTPMail Server","NAME NOT FOUND","Length: 144" "14:59:35.4980469","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\SMTP User","NAME NOT FOUND","Length: 144" "14:59:35.4981363","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\SMTP User","NAME NOT FOUND","Length: 144" "14:59:35.4982260","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\SMTP User","NAME NOT FOUND","Length: 144" "14:59:35.4983165","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\POP3 Password2","NAME NOT FOUND","Length: 144" "14:59:35.4984067","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\POP3 Password2","NAME NOT FOUND","Length: 144" "14:59:35.4984972","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\POP3 Password2","NAME NOT FOUND","Length: 144" "14:59:35.4985878","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\IMAP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4986777","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\IMAP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4987680","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\IMAP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4988582","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\NNTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4989481","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\NNTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4990387","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\NNTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.4991295","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\HTTPMail Password2","NAME NOT FOUND","Length: 144" "14:59:35.4992211","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\HTTPMail Password2","NAME NOT FOUND","Length: 144" "14:59:35.4993110","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\HTTPMail Password2","NAME NOT FOUND","Length: 144" "14:59:35.4994010","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\SMTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.5029009","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\SMTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.5029939","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\SMTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.5030847","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\POP3 Password","NAME NOT FOUND","Length: 144" "14:59:35.5031747","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\POP3 Password","NAME NOT FOUND","Length: 144" "14:59:35.5032646","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\POP3 Password","NAME NOT FOUND","Length: 144" "14:59:35.5033549","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\IMAP Password","NAME NOT FOUND","Length: 144" "14:59:35.5034448","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\IMAP Password","NAME NOT FOUND","Length: 144" "14:59:35.5035345","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\IMAP Password","NAME NOT FOUND","Length: 144" "14:59:35.5036247","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\NNTP Password","NAME NOT FOUND","Length: 144" "14:59:35.5037150","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\NNTP Password","NAME NOT FOUND","Length: 144" "14:59:35.5038049","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\NNTP Password","NAME NOT FOUND","Length: 144" "14:59:35.5038951","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\HTTP Password","NAME NOT FOUND","Length: 144" "14:59:35.5039851","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\HTTP Password","NAME NOT FOUND","Length: 144" "14:59:35.5040753","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\HTTP Password","NAME NOT FOUND","Length: 144" "14:59:35.5041656","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\SMTP Password","NAME NOT FOUND","Length: 144" "14:59:35.5042555","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\SMTP Password","NAME NOT FOUND","Length: 144" "14:59:35.5043452","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\SMTP Password","NAME NOT FOUND","Length: 144" "14:59:35.5044352","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\POP3 Port","NAME NOT FOUND","Length: 144" "14:59:35.5045248","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\POP3 Port","NAME NOT FOUND","Length: 144" "14:59:35.5046212","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\POP3 Port","NAME NOT FOUND","Length: 144" "14:59:35.5047112","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\SMTP Port","NAME NOT FOUND","Length: 144" "14:59:35.5048006","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\SMTP Port","NAME NOT FOUND","Length: 144" "14:59:35.5048902","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\SMTP Port","NAME NOT FOUND","Length: 144" "14:59:35.5049808","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\IMAP Port","NAME NOT FOUND","Length: 144" "14:59:35.5050704","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\IMAP Port","NAME NOT FOUND","Length: 144" "14:59:35.5051598","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\VeriSign\IMAP Port","NAME NOT FOUND","Length: 144" "14:59:35.5052827","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\SMTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.5053763","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\SMTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.5054663","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\SMTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.5055565","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\SMTP Server","NAME NOT FOUND","Length: 144" "14:59:35.5056468","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\SMTP Server","NAME NOT FOUND","Length: 144" "14:59:35.5057367","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\SMTP Server","NAME NOT FOUND","Length: 144" "14:59:35.5058267","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\POP3 Server","NAME NOT FOUND","Length: 144" "14:59:35.5059166","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\POP3 Server","NAME NOT FOUND","Length: 144" "14:59:35.5060063","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\POP3 Server","NAME NOT FOUND","Length: 144" "14:59:35.5060968","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\POP3 User Name","NAME NOT FOUND","Length: 144" "14:59:35.5061862","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\POP3 User Name","NAME NOT FOUND","Length: 144" "14:59:35.5067254","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\POP3 User Name","NAME NOT FOUND","Length: 144" "14:59:35.5068268","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\SMTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.5069249","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\SMTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.5070151","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\SMTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.5071056","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\NNTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.5071953","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\NNTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.5072855","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\NNTP Email Address","NAME NOT FOUND","Length: 144" "14:59:35.5073763","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\NNTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.5074663","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\NNTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.5075565","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\NNTP User Name","NAME NOT FOUND","Length: 144" "14:59:35.5076470","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\NNTP Server","NAME NOT FOUND","Length: 144" "14:59:35.5077367","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\NNTP Server","NAME NOT FOUND","Length: 144" "14:59:35.5078261","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\NNTP Server","NAME NOT FOUND","Length: 144" "14:59:35.5079160","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\IMAP Server","NAME NOT FOUND","Length: 144" "14:59:35.5080080","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\IMAP Server","NAME NOT FOUND","Length: 144" "14:59:35.5080976","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\IMAP Server","NAME NOT FOUND","Length: 144" "14:59:35.5085214","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\IMAP User Name","NAME NOT FOUND","Length: 144" "14:59:35.5086248","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\IMAP User Name","NAME NOT FOUND","Length: 144" "14:59:35.5087161","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\IMAP User Name","NAME NOT FOUND","Length: 144" "14:59:35.5088067","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\Email","NAME NOT FOUND","Length: 144" "14:59:35.5089050","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\Email","NAME NOT FOUND","Length: 144" "14:59:35.5089950","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\Email","NAME NOT FOUND","Length: 144" "14:59:35.5090852","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\HTTP User","NAME NOT FOUND","Length: 144" "14:59:35.5091746","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\HTTP User","NAME NOT FOUND","Length: 144" "14:59:35.5092645","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\HTTP User","NAME NOT FOUND","Length: 144" "14:59:35.5093548","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\HTTP Server URL","NAME NOT FOUND","Length: 144" "14:59:35.5130580","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\HTTP Server URL","NAME NOT FOUND","Length: 144" "14:59:35.5131513","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\HTTP Server URL","NAME NOT FOUND","Length: 144" "14:59:35.5132421","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\POP3 User","NAME NOT FOUND","Length: 144" "14:59:35.5133318","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\POP3 User","NAME NOT FOUND","Length: 144" "14:59:35.5134218","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\POP3 User","NAME NOT FOUND","Length: 144" "14:59:35.5135120","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\IMAP User","NAME NOT FOUND","Length: 144" "14:59:35.5136020","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\IMAP User","NAME NOT FOUND","Length: 144" "14:59:35.5136916","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\IMAP User","NAME NOT FOUND","Length: 144" "14:59:35.5137822","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\HTTPMail User Name","NAME NOT FOUND","Length: 144" "14:59:35.5138721","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\HTTPMail User Name","NAME NOT FOUND","Length: 144" "14:59:35.5139621","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\HTTPMail User Name","NAME NOT FOUND","Length: 144" "14:59:35.5140520","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\HTTPMail Server","NAME NOT FOUND","Length: 144" "14:59:35.5141417","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\HTTPMail Server","NAME NOT FOUND","Length: 144" "14:59:35.5142311","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\HTTPMail Server","NAME NOT FOUND","Length: 144" "14:59:35.5143208","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\SMTP User","NAME NOT FOUND","Length: 144" "14:59:35.5144102","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\SMTP User","NAME NOT FOUND","Length: 144" "14:59:35.5144998","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\SMTP User","NAME NOT FOUND","Length: 144" "14:59:35.5145901","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\POP3 Password2","NAME NOT FOUND","Length: 144" "14:59:35.5146795","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\POP3 Password2","NAME NOT FOUND","Length: 144" "14:59:35.5147689","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\POP3 Password2","NAME NOT FOUND","Length: 144" "14:59:35.5148588","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\IMAP Password2","NAME NOT FOUND","Length: 144" "14:59:35.5149482","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\IMAP Password2","NAME NOT FOUND","Length: 144" "14:59:35.5150373","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\IMAP Password2","NAME NOT FOUND","Length: 144" "14:59:35.5151273","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\NNTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.5152173","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\NNTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.5153066","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\NNTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.5153963","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\HTTPMail Password2","NAME NOT FOUND","Length: 144" "14:59:35.5154857","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\HTTPMail Password2","NAME NOT FOUND","Length: 144" "14:59:35.5155751","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\HTTPMail Password2","NAME NOT FOUND","Length: 144" "14:59:35.5156651","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\SMTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.5157548","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\SMTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.5158439","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\SMTP Password2","NAME NOT FOUND","Length: 144" "14:59:35.5159335","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\POP3 Password","NAME NOT FOUND","Length: 144" "14:59:35.5160227","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\POP3 Password","NAME NOT FOUND","Length: 144" "14:59:35.5161123","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\POP3 Password","NAME NOT FOUND","Length: 144" "14:59:35.5162020","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\IMAP Password","NAME NOT FOUND","Length: 144" "14:59:35.5162984","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\IMAP Password","NAME NOT FOUND","Length: 144" "14:59:35.5163884","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\IMAP Password","NAME NOT FOUND","Length: 144" "14:59:35.5164789","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\NNTP Password","NAME NOT FOUND","Length: 144" "14:59:35.5165685","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\NNTP Password","NAME NOT FOUND","Length: 144" "14:59:35.5166579","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\NNTP Password","NAME NOT FOUND","Length: 144" "14:59:35.5167476","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\HTTP Password","NAME NOT FOUND","Length: 144" "14:59:35.5168370","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\HTTP Password","NAME NOT FOUND","Length: 144" "14:59:35.5169264","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\HTTP Password","NAME NOT FOUND","Length: 144" "14:59:35.5170164","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\SMTP Password","NAME NOT FOUND","Length: 144" "14:59:35.5171074","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\SMTP Password","NAME NOT FOUND","Length: 144" "14:59:35.5171971","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\SMTP Password","NAME NOT FOUND","Length: 144" "14:59:35.5172868","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\POP3 Port","NAME NOT FOUND","Length: 144" "14:59:35.5216792","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\POP3 Port","NAME NOT FOUND","Length: 144" "14:59:35.5217770","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\POP3 Port","NAME NOT FOUND","Length: 144" "14:59:35.5218684","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\SMTP Port","NAME NOT FOUND","Length: 144" "14:59:35.5220265","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\SMTP Port","NAME NOT FOUND","Length: 144" "14:59:35.5221178","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\SMTP Port","NAME NOT FOUND","Length: 144" "14:59:35.5222084","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\IMAP Port","NAME NOT FOUND","Length: 144" "14:59:35.5222980","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\IMAP Port","NAME NOT FOUND","Length: 144" "14:59:35.5223877","RegQueryValue","HKCU\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere\IMAP Port","NAME NOT FOUND","Length: 144" "14:59:35.5224436","RegEnumKey","HKCU\Software\Microsoft\Internet Account Manager\Accounts","NO MORE ENTRIES","Index: 4, Length: 288" "14:59:35.5225735","RegOpenKey","HKCU\Identities\{8050BE41-0268-42B2-900E-11DE9FEDDDF7}\Software\Microsoft\Internet Account Manager\Accounts","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.5226445","RegEnumKey","HKCU\Identities","NO MORE ENTRIES","Index: 1, Length: 288" "14:59:35.5227372","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Account Manager\Outlook","NAME NOT FOUND","Length: 144" "14:59:35.5228177","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Account Manager\Outlook","NAME NOT FOUND","Length: 144" "14:59:35.5228895","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Account Manager\Outlook","NAME NOT FOUND","Length: 144" "14:59:35.5229342","RegOpenKey","HKCU\Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.5229814","RegOpenKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Microsoft Outlook Internet Settings","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.5230149","RegOpenKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.5230956","RegOpenKey","HKCU\Software\Mozilla","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.5231328","RegOpenKey","HKLM\Software\Mozilla","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.5231761","RegOpenKey","HKCU\Software\Mozilla","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.5232102","RegOpenKey","HKLM\Software\Mozilla","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:35.5250431","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\FromCacheTimeout","NAME NOT FOUND","Length: 144" "14:59:35.5250713","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SecureProtocols","NAME NOT FOUND","Length: 144" "14:59:35.5250953","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CertificateRevocation","NAME NOT FOUND","Length: 144" "14:59:35.5251182","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableKeepAlive","NAME NOT FOUND","Length: 144" "14:59:35.5251406","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisablePassport","NAME NOT FOUND","Length: 144" "14:59:35.5251632","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CacheMode","NAME NOT FOUND","Length: 144" "14:59:35.5251931","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5252233","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5252501","RegOpenKey","HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5254356","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5254624","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5254878","RegOpenKey","HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5255783","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyHttp1.1","NAME NOT FOUND","Length: 144" "14:59:35.5256015","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyHttp1.1","NAME NOT FOUND","Length: 144" "14:59:35.5257069","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableBasicOverClearChannel","NAME NOT FOUND","Length: 144" "14:59:35.5257300","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Read" "14:59:35.5257566","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Read" "14:59:35.5257828","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Read" "14:59:35.5258423","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\Feature_ClientAuthCertFilter","NAME NOT FOUND","Length: 144" "14:59:35.5262340","RegOpenKey","HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5428490","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5428755","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5429007","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5429551","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5429820","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_AUTOPROXY_CACHE_ANAME_KB921400","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5430526","RegOpenKey","HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5430811","RegOpenKey","HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5431068","RegOpenKey","HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5431395","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5431621","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5431856","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5432376","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5432644","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_TEMPORARYFILES_FOR_NOCACHE_840387","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5433275","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5433507","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5433745","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5434250","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5434513","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_TEMPORARYFILES_FOR_NOCACHE_840386","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5435030","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5435250","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5435485","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5435988","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5436242","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\RETRY_HEADERONLYPOST_ONCONNECTIONRESET","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5436753","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5436974","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5437209","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5437712","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5437966","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CHUNK_TIMEOUT_KB914453","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5438474","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5438695","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5438930","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5439432","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5439687","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CERT_TRUST_VERIFIED_KB936882","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5440212","RegOpenKey","HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5440832","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\DisableWorkerThreadHibernation","NAME NOT FOUND","Length: 144" "14:59:35.5441357","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableWorkerThreadHibernation","NAME NOT FOUND","Length: 144" "14:59:35.5441598","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableReadRange","NAME NOT FOUND","Length: 144" "14:59:35.5441829","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SocketSendBufferLength","NAME NOT FOUND","Length: 144" "14:59:35.5442059","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SocketReceiveBufferLength","NAME NOT FOUND","Length: 144" "14:59:35.5442285","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\KeepAliveTimeout","NAME NOT FOUND","Length: 144" "14:59:35.5442514","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MaxHttpRedirects","NAME NOT FOUND","Length: 144" "14:59:35.5442746","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPerServer","NAME NOT FOUND","Length: 144" "14:59:35.5442980","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPer1_0Server","NAME NOT FOUND","Length: 144" "14:59:35.5443212","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ServerInfoTimeout","NAME NOT FOUND","Length: 144" "14:59:35.5443441","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ReceiveTimeOut","NAME NOT FOUND","Length: 144" "14:59:35.5443665","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableNTLMPreAuth","NAME NOT FOUND","Length: 144" "14:59:35.5443894","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ScavengeCacheLowerBound","NAME NOT FOUND","Length: 144" "14:59:35.5444120","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CertCacheNoValidate","NAME NOT FOUND","Length: 144" "14:59:35.5444774","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\ScavengeCacheFileLifeTime","NAME NOT FOUND","Length: 144" "14:59:35.5445319","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5445598","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5445880","RegOpenKey","HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5446889","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\ScavengeCacheFileLimit","NAME NOT FOUND","Length: 144" "14:59:35.5447118","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\ScavengeCacheFileLimit","NAME NOT FOUND","Length: 144" "14:59:35.5447934","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5448160","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5448397","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5448909","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5449168","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BUFFERBREAKING_818408","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5449685","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5449903","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5450141","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5450643","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5450903","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SKIP_POST_RETRY_ON_INTERNETWRITEFILE_KB895954","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5451454","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5451671","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5451906","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5452403","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5452655","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENSURE_FQDN_FOR_NEGOTIATE_KB899417","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5453172","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5453390","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5453621","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5454122","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5454381","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_DISABLE_NTLM_PREAUTH_IF_ABORTED_KB902409","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5454918","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5455133","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5455362","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5455854","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5456111","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PERMIT_CACHE_FOR_AUTHENTICATED_FTP_KB910274","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5456647","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5456865","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5457094","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5457588","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5457840","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WPAD_STORE_URL_AS_FQDN_KB903926","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5504178","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5504427","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5504673","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5505220","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5505480","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_CNAME_FOR_SPN_KB911149","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5506050","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5506271","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5506505","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5507011","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5507265","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_KEEP_CACHE_INDEX_OPEN_KB899342","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5507804","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5508025","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5508260","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5508760","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5509014","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WAIT_TIME_THREAD_TERMINATE_KB886801","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5509550","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5509771","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5510006","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5510511","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5510771","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FIX_CHUNKED_PROXY_SCRIPT_DOWNLOAD_KB843289","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5511355","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\HttpDefaultExpiryTimeSecs","NAME NOT FOUND","Length: 144" "14:59:35.5511609","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\FtpDefaultExpiryTimeSecs","NAME NOT FOUND","Length: 144" "14:59:35.5511844","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\GopherDefaultExpiryTimeSecs","NAME NOT FOUND","Length: 144" "14:59:35.5512073","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableCachingOfSSLPages","NAME NOT FOUND","Length: 144" "14:59:35.5512302","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\PerUserCookies","NAME NOT FOUND","Length: 144" "14:59:35.5512534","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\LeashLegacyCookies","NAME NOT FOUND","Length: 144" "14:59:35.5512763","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableNT4RasCheck","NAME NOT FOUND","Length: 144" "14:59:35.5513487","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DialupUseLanSettings","NAME NOT FOUND","Length: 144" "14:59:35.5514045","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\DialupUseLanSettings","NAME NOT FOUND","Length: 144" "14:59:35.5514850","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SendExtraCRLF","NAME NOT FOUND","Length: 144" "14:59:35.5515082","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\BypassFtpTimeCheck","NAME NOT FOUND","Length: 144" "14:59:35.5515311","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnableGopher","NAME NOT FOUND","Length: 144" "14:59:35.5515554","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ReleaseSocketDuringAuth","NAME NOT FOUND","Length: 144" "14:59:35.5516163","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ReleaseSocketDuring401Auth","NAME NOT FOUND","Length: 144" "14:59:35.5516694","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ReleaseSocketDuring401Auth","NAME NOT FOUND","Length: 144" "14:59:35.5517487","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WpadSearchAllDomains","NAME NOT FOUND","Length: 144" "14:59:35.5518102","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableLegacyPreAuthAsServer","NAME NOT FOUND","Length: 144" "14:59:35.5518632","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\DisableLegacyPreAuthAsServer","NAME NOT FOUND","Length: 144" "14:59:35.5519783","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\BypassHTTPNoCacheCheck","NAME NOT FOUND","Length: 144" "14:59:35.5520309","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\BypassHTTPNoCacheCheck","NAME NOT FOUND","Length: 144" "14:59:35.5521457","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\BypassSSLNoCacheCheck","NAME NOT FOUND","Length: 144" "14:59:35.5521979","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\BypassSSLNoCacheCheck","NAME NOT FOUND","Length: 144" "14:59:35.5523122","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttpTrace","NAME NOT FOUND","Length: 144" "14:59:35.5523667","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttpTrace","NAME NOT FOUND","Length: 144" "14:59:35.5524818","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\NoCheckAutodialOverRide","NAME NOT FOUND","Length: 144" "14:59:35.5525343","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\NoCheckAutodialOverRide","NAME NOT FOUND","Length: 144" "14:59:35.5526427","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\DontUseDNSLoadBalancing","NAME NOT FOUND","Length: 144" "14:59:35.5526927","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DontUseDNSLoadBalancing","NAME NOT FOUND","Length: 144" "14:59:35.5527162","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\NonBlockingClient32","NAME NOT FOUND","Length: 144" "14:59:35.5527698","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ShareCredsWithWinHttp","NAME NOT FOUND","Length: 144" "14:59:35.5529497","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\HeaderExclusionListForCache","NAME NOT FOUND","Length: 144" "14:59:35.5529737","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DnsCacheEnabled","NAME NOT FOUND","Length: 144" "14:59:35.5529966","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DnsCacheEntries","NAME NOT FOUND","Length: 144" "14:59:35.5530190","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DnsCacheTimeout","NAME NOT FOUND","Length: 144" "14:59:35.5530682","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnAlwaysOnPost","NAME NOT FOUND","Length: 144" "14:59:35.5530916","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnZoneCrossing","NAME NOT FOUND","Length: 144" "14:59:35.5531154","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnBadCertSending","NAME NOT FOUND","Length: 144" "14:59:35.5531670","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnBadCertRecving","NAME NOT FOUND","Length: 144" "14:59:35.5531905","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect","NAME NOT FOUND","Length: 144" "14:59:35.5532145","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AlwaysDrainOnRedirect","NAME NOT FOUND","Length: 144" "14:59:35.5532377","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnHTTPSToHTTPRedirect","NAME NOT FOUND","Length: 144" "14:59:35.5532928","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\GlobalUserOffline","NAME NOT FOUND","Length: 144" "14:59:35.5536682","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnableAutodial","NAME NOT FOUND","Length: 144" "14:59:35.5538465","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\TruncateFileName","NAME NOT FOUND","Length: 144" "14:59:35.5538786","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\BadProxyExpiresTime","NAME NOT FOUND","Length: 144" "14:59:35.5651462","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5651730","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5651987","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5652546","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5652817","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5861285","RegOpenKey","HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5862293","RegOpenKey","HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5863079","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\(Default)","NAME NOT FOUND","Length: 144" "14:59:35.5884975","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Compatible","NAME NOT FOUND","Length: 144" "14:59:35.5888146","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Version","NAME NOT FOUND","Length: 144" "14:59:35.5891057","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\UA Tokens","NO MORE ENTRIES","Index: 3, Length: 220" "14:59:35.5891610","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Pre Platform","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5891993","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Pre Platform","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.5892272","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Platform","NAME NOT FOUND","Length: 144" "14:59:35.5893471","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform","NO MORE ENTRIES","Index: 1, Length: 220" "14:59:35.5894669","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform","NO MORE ENTRIES","Index: 1, Length: 220" "14:59:35.5952998","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mswsock.dll","NAME NOT FOUND","Desired Access: Read" "14:59:35.6035246","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hnetcfg.dll","NAME NOT FOUND","Desired Access: Read" "14:59:35.6036994","RegQueryValue","HKLM\SOFTWARE\Microsoft\Rpc\SecurityService\DefaultAuthLevel","NAME NOT FOUND","Length: 144" "14:59:35.6076418","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock\Mapping","BUFFER OVERFLOW","Length: 144" "14:59:35.6076636","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock\Mapping","BUFFER OVERFLOW","Length: 144" "14:59:35.6195573","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wshtcpip.dll","NAME NOT FOUND","Desired Access: Read" "14:59:35.8432260","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DNSAPI.dll","NAME NOT FOUND","Desired Access: Read" "14:59:35.8434179","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows NT\DnsClient","NAME NOT FOUND","Desired Access: Read" "14:59:35.8434525","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\QueryAdapterName","NAME NOT FOUND","Length: 144" "14:59:35.8434766","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableAdapterDomainName","NAME NOT FOUND","Length: 144" "14:59:35.8435026","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseDomainNameDevolution","NAME NOT FOUND","Length: 144" "14:59:35.8435459","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\PrioritizeRecordData","NAME NOT FOUND","Length: 144" "14:59:35.8435643","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\PrioritizeRecordData","NAME NOT FOUND","Length: 144" "14:59:35.8435852","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\AllowUnqualifiedQuery","NAME NOT FOUND","Length: 144" "14:59:35.8436037","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\AllowUnqualifiedQuery","NAME NOT FOUND","Length: 144" "14:59:35.8436246","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\AppendToMultiLabelName","NAME NOT FOUND","Length: 144" "14:59:35.8436439","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ScreenBadTlds","NAME NOT FOUND","Length: 144" "14:59:35.8436626","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ScreenUnreachableServers","NAME NOT FOUND","Length: 144" "14:59:35.8436813","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\FilterClusterIp","NAME NOT FOUND","Length: 144" "14:59:35.8437003","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\WaitForNameErrorOnAll","NAME NOT FOUND","Length: 144" "14:59:35.8437193","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseEdns","NAME NOT FOUND","Length: 144" "14:59:35.8437381","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\QueryIpMatching","NAME NOT FOUND","Length: 144" "14:59:35.8437568","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseHostsFile","NAME NOT FOUND","Length: 144" "14:59:35.8437755","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationEnabled","NAME NOT FOUND","Length: 144" "14:59:35.8437948","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableDynamicUpdate","NAME NOT FOUND","Length: 144" "14:59:35.8438166","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterPrimaryName","NAME NOT FOUND","Length: 144" "14:59:35.8438353","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterAdapterName","NAME NOT FOUND","Length: 144" "14:59:35.8438548","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\EnableAdapterDomainNameRegistration","NAME NOT FOUND","Length: 144" "14:59:35.8438769","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterReverseLookup","NAME NOT FOUND","Length: 144" "14:59:35.8438962","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableReverseAddressRegistrations","NAME NOT FOUND","Length: 144" "14:59:35.8439177","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterWanAdapters","NAME NOT FOUND","Length: 144" "14:59:35.8439375","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableWanDynamicUpdate","NAME NOT FOUND","Length: 144" "14:59:35.8439590","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationTtl","NAME NOT FOUND","Length: 144" "14:59:35.8439783","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DefaultRegistrationTTL","NAME NOT FOUND","Length: 144" "14:59:35.8440004","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationRefreshInterval","NAME NOT FOUND","Length: 144" "14:59:35.8440197","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DefaultRegistrationRefreshInterval","NAME NOT FOUND","Length: 144" "14:59:35.8440414","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationMaxAddressCount","NAME NOT FOUND","Length: 144" "14:59:35.8440607","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\MaxNumberOfAddressesToRegister","NAME NOT FOUND","Length: 144" "14:59:35.8440820","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UpdateSecurityLevel","NAME NOT FOUND","Length: 144" "14:59:35.8441004","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\UpdateSecurityLevel","NAME NOT FOUND","Length: 144" "14:59:35.8441216","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UpdateZoneExcludeFile","NAME NOT FOUND","Length: 144" "14:59:35.8441403","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UpdateTopLevelDomainZones","NAME NOT FOUND","Length: 144" "14:59:35.8441593","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DnsTest","NAME NOT FOUND","Length: 144" "14:59:35.8441839","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxCacheSize","NAME NOT FOUND","Length: 144" "14:59:35.8442026","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxCacheTtl","NAME NOT FOUND","Length: 144" "14:59:35.8442216","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxNegativeCacheTtl","NAME NOT FOUND","Length: 144" "14:59:35.8442404","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\AdapterTimeoutLimit","NAME NOT FOUND","Length: 144" "14:59:35.8442594","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ServerPriorityTimeLimit","NAME NOT FOUND","Length: 144" "14:59:35.8442783","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxCachedSockets","NAME NOT FOUND","Length: 144" "14:59:35.8442971","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MulticastListenLevel","NAME NOT FOUND","Length: 144" "14:59:35.8443158","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MulticastSendLevel","NAME NOT FOUND","Length: 144" "14:59:35.8445222","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DnsQueryTimeouts","NAME NOT FOUND","Length: 144" "14:59:35.8445449","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DnsQuickQueryTimeouts","NAME NOT FOUND","Length: 144" "14:59:35.8445667","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DnsMulticastQueryTimeouts","NAME NOT FOUND","Length: 144" "14:59:35.8450189","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows NT\DnsClient","NAME NOT FOUND","Desired Access: Read" "14:59:35.8455238","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows NT\DnsClient","NAME NOT FOUND","Desired Access: Read" "14:59:35.8455455","RegOpenKey","HKLM\Software\Policies\Microsoft\System\DNSClient","NAME NOT FOUND","Desired Access: Query Value" "14:59:35.8457305","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DnsNbtLookupOrder","NAME NOT FOUND","Length: 144" "14:59:35.8519394","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winrnr.dll","NAME NOT FOUND","Desired Access: Read" "14:59:36.1909135","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AutodialDLL","NAME NOT FOUND","Length: 144" "14:59:36.1969802","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rasadhlp.dll","NAME NOT FOUND","Desired Access: Read" "14:59:40.9594905","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\Invoice_06202013_2QBK.exe","NAME NOT FOUND","Desired Access: Query Value, Enumerate Sub Keys" "14:59:40.9596944","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MaximizeApps","NAME NOT FOUND","Length: 144" "14:59:40.9597338","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MaximizeApps","NAME NOT FOUND","Length: 144" "14:59:40.9622157","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9622612","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetHood","NAME NOT FOUND","Length: 144" "14:59:40.9622998","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9623372","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer","NAME NOT FOUND","Length: 144" "14:59:40.9623716","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9624079","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon","NAME NOT FOUND","Length: 144" "14:59:40.9624808","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9625182","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups","NAME NOT FOUND","Length: 144" "14:59:40.9625713","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{20D04FE0-3AEA-1069-A2D8-08002B30309D}","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9625995","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9626367","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel","NAME NOT FOUND","Length: 144" "14:59:40.9626722","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9627107","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders","NAME NOT FOUND","Length: 144" "14:59:40.9627739","RegOpenKey","HKCU\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9628398","RegOpenKey","HKCU\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:40.9667467","RegOpenKey","HKCU\Software\Classes\Drive\shellex\FolderExtensions","NAME NOT FOUND","Desired Access: Enumerate Sub Keys" "14:59:40.9668090","RegOpenKey","HKCU\Software\Classes\Drive\shellex\FolderExtensions","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:40.9668568","RegOpenKey","HKCU\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9669138","RegOpenKey","HKCU\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:40.9669727","RegEnumKey","HKCR\Drive\shellex\FolderExtensions","NO MORE ENTRIES","Index: 1, Length: 288" "14:59:40.9670428","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9670839","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions","NAME NOT FOUND","Length: 144" "14:59:40.9672820","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:40.9672993","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:40.9673300","RegOpenKey","HKCU\Software\Classes\.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:40.9673814","RegOpenKey","HKCU\Software\Classes\.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:40.9674233","RegOpenKey","HKCU\Software\Classes\exefile","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:40.9674736","RegOpenKey","HKCU\Software\Classes\exefile\CurVer","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9674898","RegOpenKey","HKCR\exefile\CurVer","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9675208","RegOpenKey","HKCU\Software\Classes\exefile","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:40.9675795","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9676180","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden","NAME NOT FOUND","Length: 144" "14:59:40.9677250","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9677616","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceActiveDesktopOn","NAME NOT FOUND","Length: 144" "14:59:40.9677963","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9678320","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktop","NAME NOT FOUND","Length: 144" "14:59:40.9678667","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9678868","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9679226","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView","NAME NOT FOUND","Length: 144" "14:59:40.9679569","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9679924","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell","NAME NOT FOUND","Length: 144" "14:59:40.9680290","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9680642","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess","NAME NOT FOUND","Length: 144" "14:59:40.9680986","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9681343","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling","NAME NOT FOUND","Length: 144" "14:59:40.9681692","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9682047","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu","NAME NOT FOUND","Length: 144" "14:59:40.9683975","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden","NAME NOT FOUND","Length: 144" "14:59:40.9684302","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling","NAME NOT FOUND","Length: 144" "14:59:40.9685142","RegOpenKey","HKCU\Software\Classes\exefile\ShellEx\IconHandler","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9685318","RegOpenKey","HKCR\exefile\ShellEx\IconHandler","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9685626","RegOpenKey","HKCU\Software\Classes\SystemFileAssociations\.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:40.9685732","RegOpenKey","HKCR\SystemFileAssociations\.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:40.9686151","RegOpenKey","HKCU\Software\Classes\SystemFileAssociations\application","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:40.9686252","RegOpenKey","HKCR\SystemFileAssociations\application","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:40.9686606","RegOpenKey","HKCU\Software\Classes\exefile","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:40.9686763","RegQueryValue","HKCR\exefile\DocObject","NAME NOT FOUND","Length: 144" "14:59:40.9687062","RegOpenKey","HKCU\Software\Classes\exefile","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:40.9687215","RegQueryValue","HKCR\exefile\BrowseInPlace","NAME NOT FOUND","Length: 144" "14:59:40.9687512","RegOpenKey","HKCU\Software\Classes\exefile\Clsid","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9687671","RegOpenKey","HKCR\exefile\Clsid","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9687947","RegOpenKey","HKCU\Software\Classes\*","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:40.9688419","RegOpenKey","HKCU\Software\Classes\*\Clsid","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9688570","RegOpenKey","HKCR\*\Clsid","NAME NOT FOUND","Desired Access: Query Value" "14:59:40.9688880","RegOpenKey","HKCU\Software\Classes\exefile","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:40.9689031","RegQueryValue","HKCR\exefile\IsShortcut","NAME NOT FOUND","Length: 144" "14:59:40.9689319","RegOpenKey","HKCU\Software\Classes\exefile","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:40.9689470","RegQueryValue","HKCR\exefile\AlwaysShowExt","NAME NOT FOUND","Length: 144" "14:59:40.9689758","RegOpenKey","HKCU\Software\Classes\exefile","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:40.9689903","RegQueryValue","HKCR\exefile\NeverShowExt","NAME NOT FOUND","Length: 144" "14:59:41.0016757","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SETUPAPI.dll","NAME NOT FOUND","Desired Access: Read" "14:59:41.0018366","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\MiniNT","NAME NOT FOUND","Desired Access: All Access" "14:59:41.0021965","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\ServicePackCachePath","NAME NOT FOUND","Length: 144" "14:59:41.0023853","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\LogLevel","NAME NOT FOUND","Length: 144" "14:59:41.0023973","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\LogPath","NAME NOT FOUND","Length: 144" "14:59:41.0024088","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\AppLogLevels","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0029533","RegOpenKey","HKLM\Software\Policies\Microsoft\System\DNSclient","NAME NOT FOUND","Desired Access: Read" "14:59:41.0104263","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{18dc298f-c791-11e2-91fd-0012f0e93e3e}\Data","BUFFER OVERFLOW","Length: 144" "14:59:41.0108900","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{11948642-10a9-11e2-95b6-806d6172696f}\Data","BUFFER OVERFLOW","Length: 144" "14:59:41.0120150","RegOpenKey","HKCU\Software\Classes\Directory","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0120737","RegOpenKey","HKCU\Software\Classes\Directory\CurVer","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0120913","RegOpenKey","HKCR\Directory\CurVer","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0121226","RegOpenKey","HKCU\Software\Classes\Directory","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0122081","RegOpenKey","HKCU\Software\Classes\Directory\ShellEx\IconHandler","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0122248","RegOpenKey","HKCR\Directory\ShellEx\IconHandler","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0122586","RegOpenKey","HKCU\Software\Classes\Directory","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0122746","RegQueryValue","HKCR\Directory\DocObject","NAME NOT FOUND","Length: 144" "14:59:41.0123047","RegOpenKey","HKCU\Software\Classes\Directory","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0123198","RegQueryValue","HKCR\Directory\BrowseInPlace","NAME NOT FOUND","Length: 144" "14:59:41.0123514","RegOpenKey","HKCU\Software\Classes\Directory\Clsid","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0123673","RegOpenKey","HKCR\Directory\Clsid","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0123958","RegOpenKey","HKCU\Software\Classes\Folder","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0124450","RegOpenKey","HKCU\Software\Classes\Folder\Clsid","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0124603","RegOpenKey","HKCR\Folder\Clsid","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0124916","RegOpenKey","HKCU\Software\Classes\Directory","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0125070","RegQueryValue","HKCR\Directory\IsShortcut","NAME NOT FOUND","Length: 144" "14:59:41.0125363","RegOpenKey","HKCU\Software\Classes\Directory","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0125810","RegOpenKey","HKCU\Software\Classes\Directory","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0125961","RegQueryValue","HKCR\Directory\NeverShowExt","NAME NOT FOUND","Length: 144" "14:59:41.0160831","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0161320","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\UseDesktopIniCache","NAME NOT FOUND","Length: 144" "14:59:41.0838381","RegOpenKey","HKCU\Software\Classes\CLSID\{AEB6717E-7E19-11D0-97EE-00C04FD91972}\InProcServer32","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0839027","RegOpenKey","HKCU\Software\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0839580","RegOpenKey","HKCU\Software\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0839775","RegQueryValue","HKCR\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InProcServer32\LoadWithoutCOM","NAME NOT FOUND","Length: 144" "14:59:41.0840116","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks","NO MORE ENTRIES","Index: 1, Length: 220" "14:59:41.0840625","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Associations","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0840792","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0840996","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Associations","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0841136","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0841326","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Associations","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0841465","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0841653","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Associations","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0841792","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0842060","RegOpenKey","HKCU\Software\Classes\.exe","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0842533","RegOpenKey","HKCU\Software\Classes\.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0843094","RegOpenKey","HKCU\Software\Classes\.ade","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0843184","RegOpenKey","HKCR\.ade","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0843443","RegOpenKey","HKCU\Software\Classes\.adp","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0843530","RegOpenKey","HKCR\.adp","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0844921","RegOpenKey","HKCU\Software\Classes\.app","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0845025","RegOpenKey","HKCR\.app","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0845301","RegOpenKey","HKCU\Software\Classes\.asp","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0845751","RegOpenKey","HKCU\Software\Classes\.asp","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0846315","RegOpenKey","HKCU\Software\Classes\.bas","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0846402","RegOpenKey","HKCR\.bas","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0846656","RegOpenKey","HKCU\Software\Classes\.bat","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0847089","RegOpenKey","HKCU\Software\Classes\.bat","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0847628","RegOpenKey","HKCU\Software\Classes\.cer","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0848056","RegOpenKey","HKCU\Software\Classes\.cer","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0848595","RegOpenKey","HKCU\Software\Classes\.chm","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0849019","RegOpenKey","HKCU\Software\Classes\.chm","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0849556","RegOpenKey","HKCU\Software\Classes\.cmd","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0849986","RegOpenKey","HKCU\Software\Classes\.cmd","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0850517","RegOpenKey","HKCU\Software\Classes\.com","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0850950","RegOpenKey","HKCU\Software\Classes\.com","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0851796","RegOpenKey","HKCU\Software\Classes\.cpl","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0852238","RegOpenKey","HKCU\Software\Classes\.cpl","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0852785","RegOpenKey","HKCU\Software\Classes\.crt","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0853241","RegOpenKey","HKCU\Software\Classes\.crt","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0853783","RegOpenKey","HKCU\Software\Classes\.csh","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0853869","RegOpenKey","HKCR\.csh","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0855872","RegOpenKey","HKCU\Software\Classes\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}","NAME NOT FOUND","Desired Access: Read" "14:59:41.0856400","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\TreatAs","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0856582","RegOpenKey","HKCR\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\TreatAs","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0857305","RegOpenKey","HKCU\Software\Classes\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}","NAME NOT FOUND","Desired Access: Read" "14:59:41.0857794","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0858389","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0858585","RegQueryValue","HKCR\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32\InprocServer32","NAME NOT FOUND","Length: 144" "14:59:41.0859929","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServerX86","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0860121","RegOpenKey","HKCR\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServerX86","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0860440","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\LocalServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0860630","RegOpenKey","HKCR\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\LocalServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0860951","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0861527","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0862245","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocHandler32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0862437","RegOpenKey","HKCR\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocHandler32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0862753","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocHandlerX86","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0862940","RegOpenKey","HKCR\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocHandlerX86","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0863259","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\LocalServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0863443","RegOpenKey","HKCR\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\LocalServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0863762","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\LocalServer","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0863954","RegOpenKey","HKCR\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\LocalServer","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0864209","RegOpenKey","HKCU\Software\Classes\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}","NAME NOT FOUND","Desired Access: Read" "14:59:41.0864689","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0864859","RegQueryValue","HKCR\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\AppID","NAME NOT FOUND","Length: 144" "14:59:41.0889882","RegOpenKey","HKCU\Software\Classes\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}","NAME NOT FOUND","Desired Access: Read" "14:59:41.0890402","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\TreatAs","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0890583","RegOpenKey","HKCR\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\TreatAs","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0891287","RegOpenKey","HKCU\Software\Classes\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}","NAME NOT FOUND","Desired Access: Read" "14:59:41.0891782","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0892363","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0892559","RegQueryValue","HKCR\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32\InprocServer32","NAME NOT FOUND","Length: 144" "14:59:41.0893050","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServerX86","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0893237","RegOpenKey","HKCR\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServerX86","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0893556","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\LocalServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0893740","RegOpenKey","HKCR\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\LocalServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0894050","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0897221","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0898294","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocHandler32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0898489","RegOpenKey","HKCR\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocHandler32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0898811","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocHandlerX86","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0898998","RegOpenKey","HKCR\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocHandlerX86","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0899316","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\LocalServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0899504","RegOpenKey","HKCR\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\LocalServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0899814","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\LocalServer","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0899998","RegOpenKey","HKCR\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\LocalServer","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0900247","RegOpenKey","HKCU\Software\Classes\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}","NAME NOT FOUND","Desired Access: Read" "14:59:41.0900730","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0900903","RegQueryValue","HKCR\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\AppID","NAME NOT FOUND","Length: 144" "14:59:41.0901778","RegOpenKey","HKCU\Software\Classes\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}","NAME NOT FOUND","Desired Access: Read" "14:59:41.0902278","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0902848","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0903764","RegOpenKey","HKCU\Software\Classes\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}","NAME NOT FOUND","Desired Access: Read" "14:59:41.0904267","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\TreatAs","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0904445","RegOpenKey","HKCR\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\TreatAs","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0914712","RegOpenKey","HKCU\Software\Classes\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InProcServer32","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0915299","RegOpenKey","HKCU\Software\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.0924901","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","NAME NOT FOUND","Desired Access: Read" "14:59:41.0925093","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","NAME NOT FOUND","Desired Access: Read" "14:59:41.0930477","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\","NAME NOT FOUND","Desired Access: Read" "14:59:41.0930647","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\","NAME NOT FOUND","Desired Access: Read" "14:59:41.0930843","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\","NAME NOT FOUND","Desired Access: Read" "14:59:41.0930996","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\","NAME NOT FOUND","Desired Access: Read" "14:59:41.0931896","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0","NAME NOT FOUND","Desired Access: Read" "14:59:41.0932058","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0","NAME NOT FOUND","Desired Access: Read" "14:59:41.0953290","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1","NAME NOT FOUND","Desired Access: Read" "14:59:41.0953463","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1","NAME NOT FOUND","Desired Access: Read" "14:59:41.0956108","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2","NAME NOT FOUND","Desired Access: Read" "14:59:41.0956279","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2","NAME NOT FOUND","Desired Access: Read" "14:59:41.0957782","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3","NAME NOT FOUND","Desired Access: Read" "14:59:41.0957944","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3","NAME NOT FOUND","Desired Access: Read" "14:59:41.0959450","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4","NAME NOT FOUND","Desired Access: Read" "14:59:41.0959612","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4","NAME NOT FOUND","Desired Access: Read" "14:59:41.0960673","RegEnumKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones","NO MORE ENTRIES","Index: 5, Length: 288" "14:59:41.0961076","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read" "14:59:41.0961243","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read" "14:59:41.0961436","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read" "14:59:41.0961595","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read" "14:59:41.0962481","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0","NAME NOT FOUND","Desired Access: Read" "14:59:41.0962648","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0","NAME NOT FOUND","Desired Access: Read" "14:59:41.0964168","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1","NAME NOT FOUND","Desired Access: Read" "14:59:41.0964333","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1","NAME NOT FOUND","Desired Access: Read" "14:59:41.0966817","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2","NAME NOT FOUND","Desired Access: Read" "14:59:41.0966981","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2","NAME NOT FOUND","Desired Access: Read" "14:59:41.0968487","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3","NAME NOT FOUND","Desired Access: Read" "14:59:41.0968655","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3","NAME NOT FOUND","Desired Access: Read" "14:59:41.0970147","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4","NAME NOT FOUND","Desired Access: Read" "14:59:41.0970317","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4","NAME NOT FOUND","Desired Access: Read" "14:59:41.0971373","RegEnumKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones","NO MORE ENTRIES","Index: 5, Length: 288" "14:59:41.0972094","RegOpenKey","HKCU\Software\Classes\PROTOCOLS\Name-Space Handler\","NAME NOT FOUND","Desired Access: Read" "14:59:41.0972546","RegOpenKey","HKCU\Software\Classes\PROTOCOLS\Name-Space Handler\C\","NAME NOT FOUND","Desired Access: Read" "14:59:41.0972647","RegOpenKey","HKCR\PROTOCOLS\Name-Space Handler\C","NAME NOT FOUND","Desired Access: Read" "14:59:41.0972921","RegOpenKey","HKCU\Software\Classes\PROTOCOLS\Name-Space Handler\*\","NAME NOT FOUND","Desired Access: Read" "14:59:41.0973013","RegOpenKey","HKCR\PROTOCOLS\Name-Space Handler\*","NAME NOT FOUND","Desired Access: Read" "14:59:41.0973429","RegOpenKey","HKCU\SOFTWARE\Classes\PROTOCOLS\Handler\C","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0973653","RegOpenKey","HKCR\PROTOCOLS\Handler\C","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0973910","RegOpenKey","HKCU\SOFTWARE\Classes\PROTOCOLS\Handler\C","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.0974102","RegOpenKey","HKCR\PROTOCOLS\Handler\C","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.1064136","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.1064293","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.1064449","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.1064809","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.1065008","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESPECT_OBJECTSAFETY_POLICY_KB905547","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.1067268","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.1067444","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.1067751","RegOpenKey","HKCU\Software\Classes\.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.1068282","RegOpenKey","HKCU\Software\Classes\.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.1068704","RegOpenKey","HKCU\Software\Classes\exefile","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.1069198","RegOpenKey","HKCU\Software\Classes\exefile\CurVer","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.1069363","RegOpenKey","HKCR\exefile\CurVer","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.1069673","RegOpenKey","HKCU\Software\Classes\exefile","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.1070472","RegOpenKey","HKCU\Software\Classes\exefile\shell\open","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.1071137","RegOpenKey","HKCU\Software\Classes\exefile\shell\open\command","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.1071668","RegOpenKey","HKCU\Software\Classes\exefile\shell\open\command","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.1072218","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun","NAME NOT FOUND","Desired Access: Read" "14:59:41.1072634","RegOpenKey","HKCU\Software\Classes\exefile\shell\open\command","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.1073157","RegOpenKey","HKCU\Software\Classes\exefile\shell\open\command","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.1073327","RegQueryValue","HKCR\exefile\shell\open\command\command","NAME NOT FOUND","Length: 144" "14:59:41.1073718","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\604156.exe","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.1074171","RegOpenKey","HKCU\Software\Classes\exefile\shell\open\command","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.1074691","RegOpenKey","HKCU\Software\Classes\exefile\shell\open\command","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.1075383","RegOpenKey","HKCU\Software\Classes\exefile\shell\open\ddeexec","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.1075551","RegOpenKey","HKCR\exefile\shell\open\ddeexec","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.1075917","RegOpenKey","HKCU\Software\Classes\Applications\604156.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.1076020","RegOpenKey","HKCR\Applications\604156.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:41.1085784","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1214440339-926492609-1644491937-1003\UserPreference","NAME NOT FOUND","Length: 144" "14:59:41.1087368","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read" "14:59:41.1087706","RegQueryValue","HKCU\Control Panel\Desktop\MultiUILanguageId","NAME NOT FOUND","Length: 256" "14:59:41.1088491","RegQueryValue","HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\rik\LOCALS~1\Temp\604156.exe","NAME NOT FOUND","Length: 144" "14:59:41.1200517","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\604156.exe","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.1200810","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.1201226","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\InheritConsoleHandles","NAME NOT FOUND","Length: 144" "14:59:41.1201601","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.1201969","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun","NAME NOT FOUND","Length: 144" "14:59:41.1202316","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.1202679","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun","NAME NOT FOUND","Length: 144" "14:59:41.1203017","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\604156.exe","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.1203151","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\604156.exe","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.1203361","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.1203721","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRunasInstallPrompt","NAME NOT FOUND","Length: 144" "14:59:41.1204062","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\604156.exe","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.1237887","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls","NAME NOT FOUND","Desired Access: Query Value" "14:59:41.1238488","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\AppCompatibility\DisableAppCompat","NAME NOT FOUND","Length: 20" "14:59:41.1270774","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Apphelp.dll","NAME NOT FOUND","Desired Access: Read" "14:59:41.1307740","RegOpenKey","HKLM\System\WPA\TabletPC","NAME NOT FOUND","Desired Access: Query Value, WOW64_64Key" "14:59:41.1398056","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:41.1398360","RegOpenKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:41.1398561","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\604156.exe","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:41.1405660","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","NAME NOT FOUND","Desired Access: Query Value, Set Value" "14:59:41.1406794","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Safer\LevelObjects","NAME NOT FOUND","Desired Access: Read" "14:59:41.1407138","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\Levels","NAME NOT FOUND","Length: 536" "14:59:41.1409269","RegEnumKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths","NO MORE ENTRIES","Index: 1, Length: 280" "14:59:41.1415927","RegEnumKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes","NO MORE ENTRIES","Index: 5, Length: 280" "14:59:41.1416184","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones","NAME NOT FOUND","Desired Access: Read" "14:59:41.1416335","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths","NAME NOT FOUND","Desired Access: Read" "14:59:41.1416488","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes","NAME NOT FOUND","Desired Access: Read" "14:59:41.1416628","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones","NAME NOT FOUND","Desired Access: Read" "14:59:41.1416765","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths","NAME NOT FOUND","Desired Access: Read" "14:59:41.1416907","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes","NAME NOT FOUND","Desired Access: Read" "14:59:41.1417044","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones","NAME NOT FOUND","Desired Access: Read" "14:59:41.1417181","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths","NAME NOT FOUND","Desired Access: Read" "14:59:41.1417324","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes","NAME NOT FOUND","Desired Access: Read" "14:59:41.1417458","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones","NAME NOT FOUND","Desired Access: Read" "14:59:41.1417595","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths","NAME NOT FOUND","Desired Access: Read" "14:59:41.1417751","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes","NAME NOT FOUND","Desired Access: Read" "14:59:41.1417888","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones","NAME NOT FOUND","Desired Access: Read" "14:59:41.1418131","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths","NAME NOT FOUND","Desired Access: Read" "14:59:41.1418399","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes","NAME NOT FOUND","Desired Access: Read" "14:59:41.1418645","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones","NAME NOT FOUND","Desired Access: Read" "14:59:41.1418891","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths","NAME NOT FOUND","Desired Access: Read" "14:59:41.1419137","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes","NAME NOT FOUND","Desired Access: Read" "14:59:41.1419382","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones","NAME NOT FOUND","Desired Access: Read" "14:59:41.1419637","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths","NAME NOT FOUND","Desired Access: Read" "14:59:41.1419894","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes","NAME NOT FOUND","Desired Access: Read" "14:59:41.1420142","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones","NAME NOT FOUND","Desired Access: Read" "14:59:41.1420391","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths","NAME NOT FOUND","Desired Access: Read" "14:59:41.1420637","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes","NAME NOT FOUND","Desired Access: Read" "14:59:41.1420883","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones","NAME NOT FOUND","Desired Access: Read" "14:59:41.1421126","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths","NAME NOT FOUND","Desired Access: Read" "14:59:41.1421366","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes","NAME NOT FOUND","Desired Access: Read" "14:59:41.1421606","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones","NAME NOT FOUND","Desired Access: Read" "14:59:41.1422347","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","NAME NOT FOUND","Desired Access: Read" "14:59:41.1475786","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache","BUFFER OVERFLOW","Length: 144" "14:59:41.1476800","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\LogFileName","NAME NOT FOUND","Length: 536" "14:59:41.1477066","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","NAME NOT FOUND","Desired Access: Query Value, Set Value" "14:59:41.1477708","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\604156.exe","NAME NOT FOUND","Desired Access: Read" "14:59:47.4030415","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MaximizeApps","NAME NOT FOUND","Length: 144" "14:59:47.4030840","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MaximizeApps","NAME NOT FOUND","Length: 144" "14:59:47.4070571","RegOpenKey","HKCU\Software\Classes\Drive\shellex\FolderExtensions","NAME NOT FOUND","Desired Access: Enumerate Sub Keys" "14:59:47.4071233","RegOpenKey","HKCU\Software\Classes\Drive\shellex\FolderExtensions","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4071714","RegOpenKey","HKCU\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4072301","RegOpenKey","HKCU\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4072901","RegEnumKey","HKCR\Drive\shellex\FolderExtensions","NO MORE ENTRIES","Index: 1, Length: 288" "14:59:47.4075058","RegOpenKey","HKCU\Software\Classes\CLSID\{AEB6717E-7E19-11D0-97EE-00C04FD91972}\InProcServer32","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4075659","RegOpenKey","HKCU\Software\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4076189","RegOpenKey","HKCU\Software\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4076385","RegQueryValue","HKCR\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InProcServer32\LoadWithoutCOM","NAME NOT FOUND","Length: 144" "14:59:47.4076717","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks","NO MORE ENTRIES","Index: 1, Length: 220" "14:59:47.4077318","RegOpenKey","HKCU\Software\Classes\.exe","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4077790","RegOpenKey","HKCU\Software\Classes\.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4078349","RegOpenKey","HKCU\Software\Classes\.ade","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4078438","RegOpenKey","HKCR\.ade","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4078701","RegOpenKey","HKCU\Software\Classes\.adp","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4078785","RegOpenKey","HKCR\.adp","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4079039","RegOpenKey","HKCU\Software\Classes\.app","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4079123","RegOpenKey","HKCR\.app","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4079366","RegOpenKey","HKCU\Software\Classes\.asp","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4079799","RegOpenKey","HKCU\Software\Classes\.asp","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4080344","RegOpenKey","HKCU\Software\Classes\.bas","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4080430","RegOpenKey","HKCR\.bas","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4080682","RegOpenKey","HKCU\Software\Classes\.bat","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4081112","RegOpenKey","HKCU\Software\Classes\.bat","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4081648","RegOpenKey","HKCU\Software\Classes\.cer","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4082078","RegOpenKey","HKCU\Software\Classes\.cer","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4082615","RegOpenKey","HKCU\Software\Classes\.chm","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4083042","RegOpenKey","HKCU\Software\Classes\.chm","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4083576","RegOpenKey","HKCU\Software\Classes\.cmd","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4084003","RegOpenKey","HKCU\Software\Classes\.cmd","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4084540","RegOpenKey","HKCU\Software\Classes\.com","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4084975","RegOpenKey","HKCU\Software\Classes\.com","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4085512","RegOpenKey","HKCU\Software\Classes\.cpl","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4085942","RegOpenKey","HKCU\Software\Classes\.cpl","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4086481","RegOpenKey","HKCU\Software\Classes\.crt","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4086914","RegOpenKey","HKCU\Software\Classes\.crt","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4087448","RegOpenKey","HKCU\Software\Classes\.csh","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4087534","RegOpenKey","HKCR\.csh","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4088040","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","NAME NOT FOUND","Desired Access: Read" "14:59:47.4088227","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","NAME NOT FOUND","Desired Access: Read" "14:59:47.4088864","RegOpenKey","HKCU\SOFTWARE\Classes\PROTOCOLS\Handler\C","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4089099","RegOpenKey","HKCR\PROTOCOLS\Handler\C","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4089297","RegOpenKey","HKCU\SOFTWARE\Classes\PROTOCOLS\Handler\C","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4089487","RegOpenKey","HKCR\PROTOCOLS\Handler\C","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4199834","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4200018","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4200325","RegOpenKey","HKCU\Software\Classes\.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4200873","RegOpenKey","HKCU\Software\Classes\.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4201300","RegOpenKey","HKCU\Software\Classes\exefile","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4201792","RegOpenKey","HKCU\Software\Classes\exefile\CurVer","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4201957","RegOpenKey","HKCR\exefile\CurVer","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4202264","RegOpenKey","HKCU\Software\Classes\exefile","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4203063","RegOpenKey","HKCU\Software\Classes\exefile\shell\open","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4203658","RegOpenKey","HKCU\Software\Classes\exefile\shell\open\command","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4204194","RegOpenKey","HKCU\Software\Classes\exefile\shell\open\command","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4204912","RegOpenKey","HKCU\Software\Classes\exefile\shell\open\command","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4205432","RegOpenKey","HKCU\Software\Classes\exefile\shell\open\command","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4205605","RegQueryValue","HKCR\exefile\shell\open\command\command","NAME NOT FOUND","Length: 144" "14:59:47.4206541","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\610593.exe","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4207005","RegOpenKey","HKCU\Software\Classes\exefile\shell\open\command","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4207536","RegOpenKey","HKCU\Software\Classes\exefile\shell\open\command","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4208231","RegOpenKey","HKCU\Software\Classes\exefile\shell\open\ddeexec","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4208399","RegOpenKey","HKCR\exefile\shell\open\ddeexec","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4208748","RegOpenKey","HKCU\Software\Classes\Applications\610593.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4208854","RegOpenKey","HKCR\Applications\610593.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4219174","RegQueryValue","HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\rik\LOCALS~1\Temp\610593.exe","NAME NOT FOUND","Length: 144" "14:59:47.4330208","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\610593.exe","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4330554","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\610593.exe","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4330685","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\610593.exe","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4330909","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\610593.exe","NAME NOT FOUND","Desired Access: Query Value" "14:59:47.4373825","RegOpenKey","HKLM\System\WPA\TabletPC","NAME NOT FOUND","Desired Access: Query Value, WOW64_64Key" "14:59:47.4401924","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:47.4402220","RegOpenKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:47.4402415","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\610593.exe","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:47.4406480","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","NAME NOT FOUND","Desired Access: Query Value, Set Value" "14:59:47.4407927","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:47.4429153","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\LogFileName","NAME NOT FOUND","Length: 536" "14:59:47.4429768","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\610593.exe","NAME NOT FOUND","Desired Access: Read" "14:59:52.7058493","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MaximizeApps","NAME NOT FOUND","Length: 144" "14:59:52.7058915","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MaximizeApps","NAME NOT FOUND","Length: 144" "14:59:52.7071467","RegOpenKey","HKCU\Software\Classes\Drive\shellex\FolderExtensions","NAME NOT FOUND","Desired Access: Enumerate Sub Keys" "14:59:52.7072123","RegOpenKey","HKCU\Software\Classes\Drive\shellex\FolderExtensions","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7072612","RegOpenKey","HKCU\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7073207","RegOpenKey","HKCU\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7073802","RegEnumKey","HKCR\Drive\shellex\FolderExtensions","NO MORE ENTRIES","Index: 1, Length: 288" "14:59:52.7075987","RegOpenKey","HKCU\Software\Classes\CLSID\{AEB6717E-7E19-11D0-97EE-00C04FD91972}\InProcServer32","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7076590","RegOpenKey","HKCU\Software\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7077124","RegOpenKey","HKCU\Software\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7077325","RegQueryValue","HKCR\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InProcServer32\LoadWithoutCOM","NAME NOT FOUND","Length: 144" "14:59:52.7077652","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks","NO MORE ENTRIES","Index: 1, Length: 220" "14:59:52.7078261","RegOpenKey","HKCU\Software\Classes\.exe","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7078750","RegOpenKey","HKCU\Software\Classes\.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7079317","RegOpenKey","HKCU\Software\Classes\.ade","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7079406","RegOpenKey","HKCR\.ade","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7079669","RegOpenKey","HKCU\Software\Classes\.adp","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7079753","RegOpenKey","HKCR\.adp","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7080004","RegOpenKey","HKCU\Software\Classes\.app","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7080091","RegOpenKey","HKCR\.app","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7080337","RegOpenKey","HKCU\Software\Classes\.asp","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7080770","RegOpenKey","HKCU\Software\Classes\.asp","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7081314","RegOpenKey","HKCU\Software\Classes\.bas","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7081401","RegOpenKey","HKCR\.bas","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7081658","RegOpenKey","HKCU\Software\Classes\.bat","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7082097","RegOpenKey","HKCU\Software\Classes\.bat","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7082636","RegOpenKey","HKCU\Software\Classes\.cer","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7083069","RegOpenKey","HKCU\Software\Classes\.cer","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7113743","RegOpenKey","HKCU\Software\Classes\.chm","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7114221","RegOpenKey","HKCU\Software\Classes\.chm","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7114791","RegOpenKey","HKCU\Software\Classes\.cmd","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7115232","RegOpenKey","HKCU\Software\Classes\.cmd","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7115777","RegOpenKey","HKCU\Software\Classes\.com","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7116210","RegOpenKey","HKCU\Software\Classes\.com","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7116752","RegOpenKey","HKCU\Software\Classes\.cpl","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7117188","RegOpenKey","HKCU\Software\Classes\.cpl","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7117727","RegOpenKey","HKCU\Software\Classes\.crt","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7118160","RegOpenKey","HKCU\Software\Classes\.crt","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7118696","RegOpenKey","HKCU\Software\Classes\.csh","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7118780","RegOpenKey","HKCR\.csh","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7119302","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","NAME NOT FOUND","Desired Access: Read" "14:59:52.7119492","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","NAME NOT FOUND","Desired Access: Read" "14:59:52.7120129","RegOpenKey","HKCU\SOFTWARE\Classes\PROTOCOLS\Handler\C","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7120364","RegOpenKey","HKCR\PROTOCOLS\Handler\C","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7120562","RegOpenKey","HKCU\SOFTWARE\Classes\PROTOCOLS\Handler\C","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7120752","RegOpenKey","HKCR\PROTOCOLS\Handler\C","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7180855","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7181031","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7181316","RegOpenKey","HKCU\Software\Classes\.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7181833","RegOpenKey","HKCU\Software\Classes\.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7182238","RegOpenKey","HKCU\Software\Classes\exefile","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7182732","RegOpenKey","HKCU\Software\Classes\exefile\CurVer","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7182897","RegOpenKey","HKCR\exefile\CurVer","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7183204","RegOpenKey","HKCU\Software\Classes\exefile","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7183998","RegOpenKey","HKCU\Software\Classes\exefile\shell\open","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7184593","RegOpenKey","HKCU\Software\Classes\exefile\shell\open\command","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7185126","RegOpenKey","HKCU\Software\Classes\exefile\shell\open\command","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7185842","RegOpenKey","HKCU\Software\Classes\exefile\shell\open\command","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7186353","RegOpenKey","HKCU\Software\Classes\exefile\shell\open\command","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7186520","RegQueryValue","HKCR\exefile\shell\open\command\command","NAME NOT FOUND","Length: 144" "14:59:52.7186914","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\615843.exe","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7187367","RegOpenKey","HKCU\Software\Classes\exefile\shell\open\command","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7187895","RegOpenKey","HKCU\Software\Classes\exefile\shell\open\command","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7188577","RegOpenKey","HKCU\Software\Classes\exefile\shell\open\ddeexec","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7188741","RegOpenKey","HKCR\exefile\shell\open\ddeexec","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7189088","RegOpenKey","HKCU\Software\Classes\Applications\615843.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7189191","RegOpenKey","HKCR\Applications\615843.exe","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7218513","RegQueryValue","HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\rik\LOCALS~1\Temp\615843.exe","NAME NOT FOUND","Length: 144" "14:59:52.7301395","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\615843.exe","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7301714","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\615843.exe","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7301845","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\615843.exe","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7302071","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\615843.exe","NAME NOT FOUND","Desired Access: Query Value" "14:59:52.7347616","RegOpenKey","HKLM\System\WPA\TabletPC","NAME NOT FOUND","Desired Access: Query Value, WOW64_64Key" "14:59:52.7372823","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:52.7373111","RegOpenKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:52.7373304","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\615843.exe","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:52.7377338","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","NAME NOT FOUND","Desired Access: Query Value, Set Value" "14:59:52.7378861","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:52.7426193","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\LogFileName","NAME NOT FOUND","Length: 536" "14:59:52.7426842","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\615843.exe","NAME NOT FOUND","Desired Access: Read" "14:59:52.8195442","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SAMLIB.dll","NAME NOT FOUND","Desired Access: Read" "14:59:54.6181387","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MaximizeApps","NAME NOT FOUND","Length: 144" "14:59:54.6181787","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MaximizeApps","NAME NOT FOUND","Length: 144" "14:59:54.6311367","RegOpenKey","HKCU\Software\Classes\Drive\shellex\FolderExtensions","NAME NOT FOUND","Desired Access: Enumerate Sub Keys" "14:59:54.6312049","RegOpenKey","HKCU\Software\Classes\Drive\shellex\FolderExtensions","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:54.6312529","RegOpenKey","HKCU\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6318698","RegOpenKey","HKCU\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:54.6319866","RegEnumKey","HKCR\Drive\shellex\FolderExtensions","NO MORE ENTRIES","Index: 1, Length: 288" "14:59:54.6320807","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bat","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:54.6321165","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bat","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:54.6321461","RegOpenKey","HKCU\Software\Classes\.bat","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:54.6321986","RegOpenKey","HKCU\Software\Classes\.bat","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:54.6322408","RegOpenKey","HKCU\Software\Classes\batfile","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:54.6323123","RegOpenKey","HKCU\Software\Classes\batfile\CurVer","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6323279","RegOpenKey","HKCR\batfile\CurVer","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6323623","RegOpenKey","HKCU\Software\Classes\batfile","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:54.6324486","RegOpenKey","HKCU\Software\Classes\batfile\ShellEx\IconHandler","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6324660","RegOpenKey","HKCR\batfile\ShellEx\IconHandler","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6325012","RegOpenKey","HKCU\Software\Classes\SystemFileAssociations\.bat","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:54.6325120","RegOpenKey","HKCR\SystemFileAssociations\.bat","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:54.6325671","RegOpenKey","HKCU\Software\Classes\SystemFileAssociations\application","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:54.6325774","RegOpenKey","HKCR\SystemFileAssociations\application","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:54.6326140","RegOpenKey","HKCU\Software\Classes\batfile","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:54.6326297","RegQueryValue","HKCR\batfile\DocObject","NAME NOT FOUND","Length: 144" "14:59:54.6326598","RegOpenKey","HKCU\Software\Classes\batfile","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:54.6326749","RegQueryValue","HKCR\batfile\BrowseInPlace","NAME NOT FOUND","Length: 144" "14:59:54.6327045","RegOpenKey","HKCU\Software\Classes\batfile\Clsid","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6327202","RegOpenKey","HKCR\batfile\Clsid","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6327476","RegOpenKey","HKCU\Software\Classes\*","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:54.6327948","RegOpenKey","HKCU\Software\Classes\*\Clsid","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6328104","RegOpenKey","HKCR\*\Clsid","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6328411","RegOpenKey","HKCU\Software\Classes\batfile","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:54.6328559","RegQueryValue","HKCR\batfile\IsShortcut","NAME NOT FOUND","Length: 144" "14:59:54.6328842","RegOpenKey","HKCU\Software\Classes\batfile","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:54.6328990","RegQueryValue","HKCR\batfile\AlwaysShowExt","NAME NOT FOUND","Length: 144" "14:59:54.6329266","RegOpenKey","HKCU\Software\Classes\batfile","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:54.6329412","RegQueryValue","HKCR\batfile\NeverShowExt","NAME NOT FOUND","Length: 144" "14:59:54.6331591","RegOpenKey","HKCU\Software\Classes\CLSID\{AEB6717E-7E19-11D0-97EE-00C04FD91972}\InProcServer32","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6332163","RegOpenKey","HKCU\Software\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:54.6332686","RegOpenKey","HKCU\Software\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:54.6332881","RegQueryValue","HKCR\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InProcServer32\LoadWithoutCOM","NAME NOT FOUND","Length: 144" "14:59:54.6333203","RegEnumValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks","NO MORE ENTRIES","Index: 1, Length: 220" "14:59:54.6333800","RegOpenKey","HKCU\Software\Classes\.bat","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6334245","RegOpenKey","HKCU\Software\Classes\.bat","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:54.6334792","RegOpenKey","HKCU\Software\Classes\.ade","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6334881","RegOpenKey","HKCR\.ade","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6335136","RegOpenKey","HKCU\Software\Classes\.adp","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6335220","RegOpenKey","HKCR\.adp","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6335471","RegOpenKey","HKCU\Software\Classes\.app","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6335558","RegOpenKey","HKCR\.app","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6335803","RegOpenKey","HKCU\Software\Classes\.asp","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6336228","RegOpenKey","HKCU\Software\Classes\.asp","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:54.6336767","RegOpenKey","HKCU\Software\Classes\.bas","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6336851","RegOpenKey","HKCR\.bas","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6337359","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","NAME NOT FOUND","Desired Access: Read" "14:59:54.6337544","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","NAME NOT FOUND","Desired Access: Read" "14:59:54.6338178","RegOpenKey","HKCU\SOFTWARE\Classes\PROTOCOLS\Handler\C","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6338415","RegOpenKey","HKCR\PROTOCOLS\Handler\C","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6338614","RegOpenKey","HKCU\SOFTWARE\Classes\PROTOCOLS\Handler\C","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6338804","RegOpenKey","HKCR\PROTOCOLS\Handler\C","NAME NOT FOUND","Desired Access: Query Value" "14:59:54.6426678","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:54.6454774","RegOpenKey","HKLM\Software\Microsoft\Cryptography\Providers\Trust\DiagnosticPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","NAME NOT FOUND","Desired Access: Read" "14:59:54.6456405","RegOpenKey","HKCU\SOFTWARE\Microsoft\Cryptography\Providers\Type 001","NAME NOT FOUND","Desired Access: Read" "14:59:54.6459383","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\SafeProcessSearchMode","NAME NOT FOUND","Length: 16" "14:59:54.6659247","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rsaenh.dll","NAME NOT FOUND","Desired Access: Read" "14:59:55.0100592","RegOpenKey","HKLM\Software\Policies\Microsoft\Cryptography","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:55.0102601","RegOpenKey","HKLM\Software\Microsoft\Cryptography\Offload","NAME NOT FOUND","Desired Access: Read" "14:59:55.0105526","RegOpenKey","HKLM\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "14:59:55.0106000","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "14:59:55.0106319","RegOpenKey","HKLM\Software\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "14:59:55.0111247","RegOpenKey","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllIsMyFileType","NAME NOT FOUND","Desired Access: Read" "14:59:55.0117561","RegEnumKey","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllIsMyFileType2","NO MORE ENTRIES","Index: 4, Length: 288" "14:59:55.0123363","RegEnumKey","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllIsMyFileType2","NO MORE ENTRIES","Index: 4, Length: 288" "14:59:55.0124154","RegOpenKey","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptSIPDllIsMyFileType2","NAME NOT FOUND","Desired Access: Read" "14:59:55.0124464","RegEnumKey","HKLM\SOFTWARE\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "14:59:55.0368925","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSISIP.DLL","NAME NOT FOUND","Desired Access: Read" "14:59:55.1343211","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wshext.dll","NAME NOT FOUND","Desired Access: Read" "14:59:55.1344317","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read" "14:59:55.1344703","RegQueryValue","HKCU\Control Panel\Desktop\MultiUILanguageId","NAME NOT FOUND","Length: 256" "14:59:55.1402405","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read" "14:59:55.1402718","RegQueryValue","HKCU\Control Panel\Desktop\MultiUILanguageId","NAME NOT FOUND","Length: 256" "14:59:55.1438611","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\LogFileName","NAME NOT FOUND","Length: 536" "14:59:55.1440231","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bat","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:55.1440419","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bat","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:55.1440754","RegOpenKey","HKCU\Software\Classes\.bat","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:55.1441366","RegOpenKey","HKCU\Software\Classes\.bat","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:55.1441804","RegOpenKey","HKCU\Software\Classes\batfile","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:55.1442293","RegOpenKey","HKCU\Software\Classes\batfile\CurVer","NAME NOT FOUND","Desired Access: Query Value" "14:59:55.1442450","RegOpenKey","HKCR\batfile\CurVer","NAME NOT FOUND","Desired Access: Query Value" "14:59:55.1442743","RegOpenKey","HKCU\Software\Classes\batfile","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:55.1443559","RegOpenKey","HKCU\Software\Classes\batfile\shell\open","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:55.1444260","RegOpenKey","HKCU\Software\Classes\batfile\shell\open\command","NAME NOT FOUND","Desired Access: Query Value" "14:59:55.1444830","RegOpenKey","HKCU\Software\Classes\batfile\shell\open\command","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:55.1445570","RegOpenKey","HKCU\Software\Classes\batfile\shell\open\command","NAME NOT FOUND","Desired Access: Query Value" "14:59:55.1446090","RegOpenKey","HKCU\Software\Classes\batfile\shell\open\command","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:55.1446260","RegQueryValue","HKCR\batfile\shell\open\command\command","NAME NOT FOUND","Length: 144" "14:59:55.1446646","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\618171.bat","NAME NOT FOUND","Desired Access: Query Value" "14:59:55.1447149","RegOpenKey","HKCU\Software\Classes\batfile\shell\open\command","NAME NOT FOUND","Desired Access: Query Value" "14:59:55.1447668","RegOpenKey","HKCU\Software\Classes\batfile\shell\open\command","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:55.1448358","RegOpenKey","HKCU\Software\Classes\batfile\shell\open\ddeexec","NAME NOT FOUND","Desired Access: Query Value" "14:59:55.1448526","RegOpenKey","HKCR\batfile\shell\open\ddeexec","NAME NOT FOUND","Desired Access: Query Value" "14:59:55.1448911","RegOpenKey","HKCU\Software\Classes\Applications\618171.bat","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:55.1449015","RegOpenKey","HKCR\Applications\618171.bat","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:55.1459248","RegQueryValue","HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\rik\LOCALS~1\Temp\618171.bat","NAME NOT FOUND","Length: 144" "14:59:55.1537423","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\618171.bat","NAME NOT FOUND","Desired Access: Query Value" "14:59:55.1537836","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\618171.bat","NAME NOT FOUND","Desired Access: Query Value" "14:59:55.1537970","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\618171.bat","NAME NOT FOUND","Desired Access: Query Value" "14:59:55.1538188","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\618171.bat","NAME NOT FOUND","Desired Access: Query Value" "14:59:55.1570030","RegOpenKey","HKLM\System\WPA\TabletPC","NAME NOT FOUND","Desired Access: Query Value, WOW64_64Key" "14:59:55.1602319","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:55.1602632","RegOpenKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:55.1603213","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\618171.bat","NAME NOT FOUND","Desired Access: Read, WOW64_64Key" "14:59:55.1607311","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","NAME NOT FOUND","Desired Access: Query Value, Set Value" "14:59:55.1608767","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","NAME NOT FOUND","Desired Access: Maximum Allowed" "14:59:55.1634178","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\LogFileName","NAME NOT FOUND","Length: 536" "14:59:55.1690283","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe","NAME NOT FOUND","Desired Access: Read" "14:59:55.3318448","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles","NAME NOT FOUND","Length: 20" --- #MalwareMustDie | @unixfreaxjp