Teil 2 Code:
"Time of Day","Process Name","PID","Operation","Path","Result","Detail"
"01:38:41,8794575","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Thread Create","","SUCCESS","Thread ID: 5660"
"01:38:41,8815454","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Load Image","C:\Users\thoma\AppData\Local\Temp\6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","SUCCESS","Image Base: 0xdf0000, Image Size: 0x18000"
"01:38:41,8816073","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Load Image","C:\Windows\System32\ntdll.dll","SUCCESS","Image Base: 0x7ffa42130000, Image Size: 0x1f5000"
"01:38:41,8816746","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Load Image","C:\Windows\SysWOW64\ntdll.dll","SUCCESS","Image Base: 0x76f40000, Image Size: 0x1a3000"
"01:38:41,8818138","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFile","C:\Windows\Prefetch\6DC8E1C9-BDA7-4C8A-A834-54798-20215CB6.pf","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened"
"01:38:41,8818629","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","QueryStandardInformationFile","C:\Windows\Prefetch\6DC8E1C9-BDA7-4C8A-A834-54798-20215CB6.pf","SUCCESS","AllocationSize: 4.096, EndOfFile: 3.656, NumberOfLinks: 1, DeletePending: False, Directory: False"
"01:38:41,8818855","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","ReadFile","C:\Windows\Prefetch\6DC8E1C9-BDA7-4C8A-A834-54798-20215CB6.pf","SUCCESS","Offset: 0, Length: 3.656, Priority: Normal"
"01:38:41,8819639","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CloseFile","C:\Windows\Prefetch\6DC8E1C9-BDA7-4C8A-A834-54798-20215CB6.pf","SUCCESS",""
"01:38:41,8850363","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value"
"01:38:41,8850514","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value"
"01:38:41,8850658","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\RaiseExceptionOnPossibleDeadlock","NAME NOT FOUND","Length: 80"
"01:38:41,8850810","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS",""
"01:38:41,8850989","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Segment Heap","REPARSE","Desired Access: Query Value"
"01:38:41,8851117","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager\Segment Heap","NAME NOT FOUND","Desired Access: Query Value"
"01:38:41,8851516","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value, Enumerate Sub Keys"
"01:38:41,8851672","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys"
"01:38:41,8851814","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies","NAME NOT FOUND","Length: 24"
"01:38:41,8852108","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS",""
"01:38:41,8856085","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFile","C:\Windows","SUCCESS","Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"01:38:41,8857911","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Load Image","C:\Windows\System32\wow64.dll","SUCCESS","Image Base: 0x7ffa402c0000, Image Size: 0x59000"
"01:38:41,8859678","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Load Image","C:\Windows\System32\wow64win.dll","SUCCESS","Image Base: 0x7ffa41540000, Image Size: 0x83000"
"01:38:41,8867837","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFile","C:\Windows\System32\wow64log.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"01:38:41,8872331","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFile","C:\Windows","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"01:38:41,8872813","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","QueryNameInformationFile","C:\Windows","SUCCESS","Name: \Windows"
"01:38:41,8873009","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CloseFile","C:\Windows","SUCCESS",""
"01:38:41,8873745","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\Software\Microsoft\Wow64\x86","SUCCESS","Desired Access: Read"
"01:38:41,8874011","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\Wow64\x86\6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","NAME NOT FOUND","Length: 520"
"01:38:41,8874160","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\Wow64\x86\(Default)","SUCCESS","Type: REG_SZ, Length: 26, Data: wow64cpu.dll"
"01:38:41,8874321","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\Wow64\x86","SUCCESS",""
"01:38:41,8875623","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Load Image","C:\Windows\System32\wow64cpu.dll","SUCCESS","Image Base: 0x76f30000, Image Size: 0xa000"
"01:38:41,8878367","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value"
"01:38:41,8878543","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value"
"01:38:41,8878734","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:41,8878859","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\RaiseExceptionOnPossibleDeadlock","NAME NOT FOUND","Length: 80"
"01:38:41,8879072","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS",""
"01:38:41,8879249","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Segment Heap","REPARSE","Desired Access: Query Value"
"01:38:41,8879389","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager\Segment Heap","NAME NOT FOUND","Desired Access: Query Value"
"01:38:41,8879796","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value, Enumerate Sub Keys"
"01:38:41,8879923","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys"
"01:38:41,8880070","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:41,8880225","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies","NAME NOT FOUND","Length: 24"
"01:38:41,8880364","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS",""
"01:38:41,8883756","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFile","C:\Users\thoma\AppData\Local\Temp","SUCCESS","Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"01:38:41,8885083","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Load Image","C:\Windows\SysWOW64\kernel32.dll","SUCCESS","Image Base: 0x75310000, Image Size: 0xf0000"
"01:38:41,8886869","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Load Image","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","Image Base: 0x76640000, Image Size: 0x214000"
"01:38:41,8888836","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFile","C:\Program Files\AVAST Software\Avast\x86\aswhook.dll","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"01:38:41,8889071","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","QueryBasicInformationFile","C:\Program Files\AVAST Software\Avast\x86\aswhook.dll","SUCCESS","CreationTime: 03.06.2021 11:14:38, LastAccessTime: 28.06.2021 01:38:32, LastWriteTime: 03.06.2021 11:14:38, ChangeTime: 03.06.2021 11:14:50, FileAttributes: A"
"01:38:41,8889178","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CloseFile","C:\Program Files\AVAST Software\Avast\x86\aswhook.dll","SUCCESS",""
"01:38:41,8890185","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFile","C:\Program Files\AVAST Software\Avast\x86\aswhook.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
"01:38:41,8890537","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","QueryEAFile","C:\Program Files\AVAST Software\Avast\x86\aswhook.dll","SUCCESS",""
"01:38:41,8890756","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","FileSystemControl","C:\Program Files\AVAST Software\Avast\x86\aswhook.dll","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"01:38:41,8891054","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFileMapping","C:\Program Files\AVAST Software\Avast\x86\aswhook.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE"
"01:38:41,8891333","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\CI","REPARSE","Desired Access: Read"
"01:38:41,8891494","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\CI","SUCCESS","Desired Access: Read"
"01:38:41,8891625","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Disable26178932","NAME NOT FOUND","Length: 20"
"01:38:41,8891755","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Control\CI","SUCCESS",""
"01:38:41,8891880","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\CI","REPARSE","Desired Access: Query Value"
"01:38:41,8891998","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\CI","SUCCESS","Desired Access: Query Value"
"01:38:41,8892115","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Disable26178932","NAME NOT FOUND","Length: 80"
"01:38:41,8892232","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Control\CI","SUCCESS",""
"01:38:41,8892350","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFileMapping","C:\Program Files\AVAST Software\Avast\x86\aswhook.dll","SUCCESS","SyncType: SyncTypeOther"
"01:38:41,8892935","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Load Image","C:\Program Files\AVAST Software\Avast\x86\aswhook.dll","SUCCESS","Image Base: 0x6edf0000, Image Size: 0x10000"
"01:38:41,8893453","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CloseFile","C:\Program Files\AVAST Software\Avast\x86\aswhook.dll","SUCCESS",""
"01:38:41,8900582","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFile","C:\Windows\System32\conhost.exe","SUCCESS","Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
"01:38:41,8901088","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFileMapping","C:\Windows\System32\conhost.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE"
"01:38:41,8901339","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\CI","REPARSE","Desired Access: Read"
"01:38:41,8901477","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\CI","SUCCESS","Desired Access: Read"
"01:38:41,8901603","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Disable26178932","NAME NOT FOUND","Length: 20"
"01:38:41,8901736","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Control\CI","SUCCESS",""
"01:38:41,8901894","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\CI","REPARSE","Desired Access: Query Value"
"01:38:41,8902117","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\CI","SUCCESS","Desired Access: Query Value"
"01:38:41,8902288","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Disable26178932","NAME NOT FOUND","Length: 80"
"01:38:41,8902449","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Control\CI","SUCCESS",""
"01:38:41,8902626","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFileMapping","C:\Windows\System32\conhost.exe","SUCCESS","SyncType: SyncTypeOther"
"01:38:41,8902916","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Conhost.exe","NAME NOT FOUND","Desired Access: Query Value, Enumerate Sub Keys"
"01:38:41,8903223","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","QuerySecurityFile","C:\Windows\System32\conhost.exe","SUCCESS","Information: Label"
"01:38:41,8903597","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","QueryNameInformationFile","C:\Windows\System32\conhost.exe","SUCCESS","Name: \Windows\System32\conhost.exe"
"01:38:41,8907485","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","FileSystemControl","C:\Windows\System32\conhost.exe","SUCCESS","Control: FSCTL_READ_FILE_USN_DATA"
"01:38:41,8907744","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","QueryStandardInformationFile","C:\Windows\System32\conhost.exe","SUCCESS","AllocationSize: 876.544, EndOfFile: 875.008, NumberOfLinks: 2, DeletePending: False, Directory: False"
"01:38:41,8907941","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","QueryStandardInformationFile","C:\Windows\System32\conhost.exe","SUCCESS","AllocationSize: 876.544, EndOfFile: 875.008, NumberOfLinks: 2, DeletePending: False, Directory: False"
"01:38:41,8908120","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","ReadFile","C:\Windows\System32\conhost.exe","SUCCESS","Offset: 0, Length: 2, Priority: Normal"
"01:38:41,8908441","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","ReadFile","C:\Windows\System32\conhost.exe","SUCCESS","Offset: 60, Length: 4"
"01:38:41,8908562","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","ReadFile","C:\Windows\System32\conhost.exe","SUCCESS","Offset: 248, Length: 4"
"01:38:41,8908660","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","ReadFile","C:\Windows\System32\conhost.exe","SUCCESS","Offset: 252, Length: 20"
"01:38:41,8908747","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","ReadFile","C:\Windows\System32\conhost.exe","SUCCESS","Offset: 416, Length: 4"
"01:38:41,8908840","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","ReadFile","C:\Windows\System32\conhost.exe","SUCCESS","Offset: 875.000, Length: 8"
"01:38:41,8908954","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","ReadFile","C:\Windows\System32\conhost.exe","SUCCESS","Offset: 874.952, Length: 8"
"01:38:41,8909679","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","QuerySecurityFile","C:\Windows\System32\conhost.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label, Attribute, Process Trust Label, 0x100"
"01:38:41,8909839","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","QueryFileInternalInformationFile","C:\Windows\System32\conhost.exe","SUCCESS","IndexNumber: 0x10000001c623e"
"01:38:41,8910008","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","FileSystemControl","C:\Windows\System32\conhost.exe","SUCCESS","Control: FSCTL_GET_NTFS_VOLUME_DATA"
"01:38:41,8910743","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Services\aswSnx","SUCCESS","Desired Access: Read"
"01:38:41,8910975","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Services\aswSnx","SUCCESS",""
"01:38:41,8912625","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFile","C:\ProgramData\AVAST Software\Avast\snx_lconfig.xml","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"01:38:41,8913168","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","QueryStandardInformationFile","C:\ProgramData\AVAST Software\Avast\snx_lconfig.xml","SUCCESS","AllocationSize: 4.096, EndOfFile: 446, NumberOfLinks: 1, DeletePending: False, Directory: False"
"01:38:41,8913372","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","ReadFile","C:\ProgramData\AVAST Software\Avast\snx_lconfig.xml","SUCCESS","Offset: 0, Length: 446, Priority: Normal"
"01:38:41,8913859","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CloseFile","C:\ProgramData\AVAST Software\Avast\snx_lconfig.xml","SUCCESS",""
"01:38:41,8916255","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFile","C:\Windows\System32\conhost.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
"01:38:41,8916944","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","QueryNameInformationFile","C:\Windows\System32\conhost.exe","BUFFER OVERFLOW","Name: \Windo"
"01:38:41,8917193","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","QueryNameInformationFile","C:\Windows\System32\conhost.exe","SUCCESS","Name: \Windows\System32\conhost.exe"
"01:38:41,8919330","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CloseFile","C:\Windows\System32\conhost.exe","SUCCESS",""
"01:38:41,8935417","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-4198695647-2910091461-4277131257-1001","SUCCESS","Desired Access: All Access"
"01:38:41,8935568","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-4198695647-2910091461-4277131257-1001\\Device\HarddiskVolume8\Windows\System32\conhost.exe","SUCCESS","Type: REG_BINARY, Length: 24, Data: ..."
"01:38:41,8935713","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetValue","HKLM\System\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-4198695647-2910091461-4277131257-1001\\Device\HarddiskVolume8\Windows\System32\conhost.exe","SUCCESS","Type: REG_BINARY, Length: 24, Data: ..."
"01:38:41,8936579","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-4198695647-2910091461-4277131257-1001","SUCCESS",""
"01:38:41,8936716","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\BAM","REPARSE","Desired Access: Query Value"
"01:38:41,8936849","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager\BAM","NAME NOT FOUND","Desired Access: Query Value"
"01:38:41,8960744","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Process Create","C:\WINDOWS\System32\Conhost.exe","SUCCESS","PID: 19684, Command line: \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1"
"01:38:41,8961131","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CloseFile","C:\Windows\System32\conhost.exe","SUCCESS",""
"01:38:42,0673296","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\3c74afb9-8d82-44e3-b52c-365dbf48382a","NAME NOT FOUND","Length: 528"
"01:38:42,0674136","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","QueryNameInformationFile","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","Name: \Windows\SysWOW64\KernelBase.dll"
"01:38:42,0675244","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\05f95efe-7f75-49c7-a994-60a55cc09571","NAME NOT FOUND","Length: 528"
"01:38:42,0675917","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","QueryNameInformationFile","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","Name: \Windows\SysWOW64\KernelBase.dll"
"01:38:42,0679254","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","REPARSE","Desired Access: Query Value, Set Value"
"01:38:42,0679520","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","NAME NOT FOUND","Desired Access: Query Value, Set Value"
"01:38:42,0679714","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Srp\GP\DLL","REPARSE","Desired Access: Read"
"01:38:42,0679875","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Srp\GP\DLL","NAME NOT FOUND","Desired Access: Read"
"01:38:42,0680169","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\Safer\CodeIdentifiers","REPARSE","Desired Access: Query Value"
"01:38:42,0680360","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers","SUCCESS","Desired Access: Query Value"
"01:38:42,0680534","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,0680632","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled","NAME NOT FOUND","Length: 80"
"01:38:42,0680835","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers","SUCCESS",""
"01:38:42,0681078","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","NAME NOT FOUND","Desired Access: Query Value"
"01:38:42,0681389","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\FileSystem\","REPARSE","Desired Access: Read"
"01:38:42,0681486","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\FileSystem","SUCCESS","Desired Access: Read"
"01:38:42,0681681","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\FileSystem","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,0681809","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\FileSystem\LongPathsEnabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"01:38:42,0682060","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Control\FileSystem","SUCCESS",""
"01:38:42,0682228","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\FileSystem\","REPARSE","Desired Access: Read"
"01:38:42,0682323","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\FileSystem","SUCCESS","Desired Access: Read"
"01:38:42,0682430","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\FileSystem","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,0682532","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\FileSystem\LPGO","NAME NOT FOUND","Length: 20"
"01:38:42,0682714","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Control\FileSystem","SUCCESS",""
"01:38:42,0687762","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Load Image","C:\Windows\SysWOW64\crypt32.dll","SUCCESS","Image Base: 0x75110000, Image Size: 0x101000"
"01:38:42,0689490","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Load Image","C:\Windows\SysWOW64\ucrtbase.dll","SUCCESS","Image Base: 0x76c20000, Image Size: 0x120000"
"01:38:42,0711512","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Thread Create","","SUCCESS","Thread ID: 12284"
"01:38:42,0717516","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions","REPARSE","Desired Access: Read"
"01:38:42,0717697","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions","SUCCESS","Desired Access: Read"
"01:38:42,0717941","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,0718059","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions\(Default)","SUCCESS","Type: REG_SZ, Length: 18, Data: 00060305"
"01:38:42,0718243","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions\000603xx","SUCCESS","Type: REG_SZ, Length: 26, Data: kernel32.dll"
"01:38:42,0719233","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value, Enumerate Sub Keys"
"01:38:42,0719447","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys"
"01:38:42,0719671","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,0719799","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies","NAME NOT FOUND","Length: 24"
"01:38:42,0719957","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS",""
"01:38:42,0720904","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Thread Create","","SUCCESS","Thread ID: 11532"
"01:38:42,0724063","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","QueryNameInformationFile","C:\Users\thoma\AppData\Local\Temp\6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","SUCCESS","Name: \Users\thoma\AppData\Local\Temp\6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe"
"01:38:42,0724492","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","REPARSE","Desired Access: Read"
"01:38:42,0724652","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS","Desired Access: Read"
"01:38:42,0724880","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,0725002","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale\de-DE","NAME NOT FOUND","Length: 532"
"01:38:42,0725164","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS",""
"01:38:42,0725353","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","REPARSE","Desired Access: Read"
"01:38:42,0725499","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","SUCCESS","Desired Access: Read"
"01:38:42,0725655","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,0725757","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale\de-DE","NAME NOT FOUND","Length: 532"
"01:38:42,0725878","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","SUCCESS",""
"01:38:42,0726100","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","REPARSE","Desired Access: Read"
"01:38:42,0726219","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS","Desired Access: Read"
"01:38:42,0726350","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,0726489","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale\en-US","NAME NOT FOUND","Length: 532"
"01:38:42,0726667","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS",""
"01:38:42,0726934","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","REPARSE","Desired Access: Read"
"01:38:42,0727110","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","SUCCESS","Desired Access: Read"
"01:38:42,0727345","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,0727498","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale\en-US","NAME NOT FOUND","Length: 532"
"01:38:42,0727667","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","SUCCESS",""
"01:38:42,0728108","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions\000603xx","SUCCESS","Type: REG_SZ, Length: 26, Data: kernel32.dll"
"01:38:42,0730284","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFile","C:\Windows\Globalization\Sorting\SortDefault.nls","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
"01:38:42,0731827","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFileMapping","C:\Windows\Globalization\Sorting\SortDefault.nls","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE"
"01:38:42,0732025","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","QueryStandardInformationFile","C:\Windows\Globalization\Sorting\SortDefault.nls","SUCCESS","AllocationSize: 3.375.104, EndOfFile: 3.371.404, NumberOfLinks: 2, DeletePending: False, Directory: False"
"01:38:42,0735542","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFileMapping","C:\Windows\Globalization\Sorting\SortDefault.nls","SUCCESS","SyncType: SyncTypeOther"
"01:38:42,0736166","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CloseFile","C:\Windows\Globalization\Sorting\SortDefault.nls","SUCCESS",""
"01:38:42,0737190","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids","REPARSE","Desired Access: Read"
"01:38:42,0737399","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids","SUCCESS","Desired Access: Read"
"01:38:42,0737632","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,0737789","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids\en-US","NAME NOT FOUND","Length: 90"
"01:38:42,0738000","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids\en","NAME NOT FOUND","Length: 90"
"01:38:42,0738946","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM","SUCCESS","Desired Access: Maximum Allowed, Granted Access: Read"
"01:38:42,0739227","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"01:38:42,0739329","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: Name"
"01:38:42,0739506","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\crypt32","REPARSE","Desired Access: Read"
"01:38:42,0739696","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Services\crypt32","SUCCESS","Desired Access: Read"
"01:38:42,0739866","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\crypt32","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,0739983","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Services\crypt32\DiagLevel","NAME NOT FOUND","Length: 16"
"01:38:42,0740118","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Services\crypt32\DiagMatchAnyMask","NAME NOT FOUND","Length: 20"
"01:38:42,0740313","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Services\crypt32","SUCCESS",""
"01:38:42,0740514","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"01:38:42,0740627","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: Name"
"01:38:42,0740833","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\crypt32","REPARSE","Desired Access: Read"
"01:38:42,0740976","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Services\crypt32","SUCCESS","Desired Access: Read"
"01:38:42,0741113","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\crypt32","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,0754324","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Thread Create","","SUCCESS","Thread ID: 3692"
"01:38:42,0755260","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"01:38:42,0755481","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: Name"
"01:38:42,0756064","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read"
"01:38:42,0756576","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,0757031","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0"
"01:38:42,0757742","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0757987","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read"
"01:38:42,0758596","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0758809","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv","SUCCESS","Desired Access: Read"
"01:38:42,0759081","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv","SUCCESS","Index: 0, Name: #16"
"01:38:42,0759393","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0759693","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16","SUCCESS","Desired Access: Read"
"01:38:42,0760003","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16","SUCCESS","Query: Cached, SubKeys: 0, Values: 2"
"01:38:42,0760303","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\cryptnet.dll"
"01:38:42,0760494","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 36, Data: LdapProvOpenStore"
"01:38:42,0783740","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0783872","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCreateKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY"
"01:38:42,0785302","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,0785587","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,0785854","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\CRLs","SUCCESS",""
"01:38:42,0786190","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0786387","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCreateKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY"
"01:38:42,0787953","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,0788158","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,0788350","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\CTLs","SUCCESS",""
"01:38:42,0788746","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"01:38:42,0788873","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKU","SUCCESS","Query: Name"
"01:38:42,0789077","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access"
"01:38:42,0790487","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Load Image","C:\Windows\SysWOW64\sechost.dll","SUCCESS","Image Base: 0x75400000, Image Size: 0x75000"
"01:38:42,0794133","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Load Image","C:\Windows\SysWOW64\rpcrt4.dll","SUCCESS","Image Base: 0x76af0000, Image Size: 0xbf000"
"01:38:42,0798421","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\ca967c75-04bf-40b5-9a16-98b5f9332a92","NAME NOT FOUND","Length: 528"
"01:38:42,0799237","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","QueryNameInformationFile","C:\Windows\SysWOW64\sechost.dll","SUCCESS","Name: \Windows\SysWOW64\sechost.dll"
"01:38:42,0800244","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\b6fd710b-f783-4b1c-ab9c-c68099dcc0c7","NAME NOT FOUND","Length: 528"
"01:38:42,0800806","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","QueryNameInformationFile","C:\Windows\SysWOW64\sechost.dll","SUCCESS","Name: \Windows\SysWOW64\sechost.dll"
"01:38:42,0801430","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"01:38:42,0801903","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKCU","SUCCESS","Query: Name"
"01:38:42,0803545","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","Desired Access: Read"
"01:38:42,0803997","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,0804838","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKeySecurity","HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS",""
"01:38:42,0805324","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates","BUFFER OVERFLOW","Length: 12"
"01:38:42,0805629","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates","SUCCESS","Type: REG_BINARY, Length: 24, Data: ...
"01:38:42,0806038","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS",""
"01:38:42,0806377","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKCU","SUCCESS",""
"01:38:42,0806785","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\Root","SUCCESS",""
"01:38:42,0807162","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKCU","SUCCESS",""
"01:38:42,0807937","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"01:38:42,0808241","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: Name"
"01:38:42,0808703","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\ROOT\PhysicalStores","REPARSE","Desired Access: Read"
"01:38:42,0809095","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\PhysicalStores","NAME NOT FOUND","Desired Access: Read"
"01:38:42,0809736","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"01:38:42,0810126","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: Name"
"01:38:42,0810489","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\ROOT","REPARSE","Desired Access: Read"
"01:38:42,0810825","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","Desired Access: Read"
"01:38:42,0811155","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,0811549","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS",""
"01:38:42,0811860","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"01:38:42,0812004","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: Name"
"01:38:42,0812277","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","REPARSE","Desired Access: Read"
"01:38:42,0812539","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","NAME NOT FOUND","Desired Access: Read"
"01:38:42,0813076","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"01:38:42,0813218","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: Name"
"01:38:42,0813479","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\ROOT","REPARSE","Desired Access: Read"
"01:38:42,0813645","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","Desired Access: Read"
"01:38:42,0813806","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,0814023","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0814172","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","Desired Access: Read"
"01:38:42,0814420","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0814621","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Desired Access: Read"
"01:38:42,0814827","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: Cached, SubKeys: 22, Values: 0"
"01:38:42,0816149","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: Cached, SubKeys: 22, Values: 0"
"01:38:42,0816400","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 0, Name: 0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8"
"01:38:42,0816753","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0817000","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\xxx","SUCCESS","Desired Access: Read"
"01:38:42,0817289","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\xxx\Blob","BUFFER OVERFLOW","Length: 12"
"01:38:42,0817517","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\xxx\Blob","BUFFER OVERFLOW","Length: 144"
"01:38:42,0817761","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\xxx\Blob","SUCCESS","Type: REG_BINARY, Length: 2.001, Data:
"01:38:42,0818036","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\0xxx","SUCCESS",""
"01:38:42,0818525","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"01:38:42,0818698","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: Name"
"01:38:42,0819044","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read"
"01:38:42,0819344","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,0819674","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0"
"01:38:42,0820112","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0820340","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read"
"01:38:42,0820742","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0820966","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllDecodeObjectEx","NAME NOT FOUND","Desired Access: Read"
"01:38:42,0821228","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS",""
"01:38:42,0821429","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1"
"01:38:42,0821776","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0821958","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read"
"01:38:42,0822280","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0822484","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Desired Access: Read"
"01:38:42,0822773","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Index: 0, Name: 1.2.840.113549.1.9.16.1.1"
"01:38:42,0823172","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0823416","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1","SUCCESS","Desired Access: Read"
"01:38:42,0823617","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1","SUCCESS","Query: Cached, SubKeys: 0, Values: 2"
"01:38:42,0823817","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll"
"01:38:42,0823995","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 38, Data: EssReceiptDecodeEx"
"01:38:42,0824359","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1","SUCCESS",""
"01:38:42,0824522","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Index: 1, Name: 1.2.840.113549.1.9.16.2.1"
"01:38:42,0824901","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0825180","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1","SUCCESS","Desired Access: Read"
"01:38:42,0825712","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1","SUCCESS","Query: Cached, SubKeys: 0, Values: 2"
"01:38:42,0826080","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll"
"01:38:42,0826404","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 52, Data: EssReceiptRequestDecodeEx"
"01:38:42,0826929","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1","SUCCESS",""
"01:38:42,0827241","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Index: 2, Name: 1.2.840.113549.1.9.16.2.11"
"01:38:42,0827686","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0828033","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11","SUCCESS","Desired Access: Read"
"01:38:42,0828403","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11","SUCCESS","Query: Cached, SubKeys: 0, Values: 2"
"01:38:42,0828718","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll"
"01:38:42,0829100","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 58, Data: EssKeyExchPreferenceDecodeEx"
"01:38:42,0829528","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11","SUCCESS",""
"01:38:42,0829858","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Index: 3, Name: 1.2.840.113549.1.9.16.2.12"
"01:38:42,0830199","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0830491","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12","SUCCESS","Desired Access: Read"
"01:38:42,0830947","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12","SUCCESS","Query: Cached, SubKeys: 0, Values: 2"
"01:38:42,0831255","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll"
"01:38:42,0831382","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: EssSignCertificateDecodeEx"
"01:38:42,0831604","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12","SUCCESS",""
"01:38:42,0831743","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Index: 4, Name: 1.2.840.113549.1.9.16.2.2"
"01:38:42,0831946","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0832074","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2","SUCCESS","Desired Access: Read"
"01:38:42,0832238","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2","SUCCESS","Query: Cached, SubKeys: 0, Values: 2"
"01:38:42,0832431","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll"
"01:38:42,0832556","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: EssSecurityLabelDecodeEx"
"01:38:42,0832835","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2","SUCCESS",""
"01:38:42,0833029","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Index: 5, Name: 1.2.840.113549.1.9.16.2.3"
"01:38:42,0833307","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0833472","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3","SUCCESS","Desired Access: Read"
"01:38:42,0833666","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3","SUCCESS","Query: Cached, SubKeys: 0, Values: 2"
"01:38:42,0833826","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll"
"01:38:42,0833987","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 42, Data: EssMLHistoryDecodeEx"
"01:38:42,0834233","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3","SUCCESS",""
"01:38:42,0834401","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Index: 6, Name: 1.2.840.113549.1.9.16.2.4"
"01:38:42,0834633","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0834786","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4","SUCCESS","Desired Access: Read"
"01:38:42,0834978","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4","SUCCESS","Query: Cached, SubKeys: 0, Values: 2"
"01:38:42,0835125","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll"
"01:38:42,0835263","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 46, Data: EssContentHintDecodeEx"
"01:38:42,0835453","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4","SUCCESS",""
"01:38:42,0835595","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","NO MORE ENTRIES","Index: 7, Length: 288"
"01:38:42,0835836","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS",""
"01:38:42,0836047","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS",""
"01:38:42,0836224","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288"
"01:38:42,0836444","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS",""
"01:38:42,0837488","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value"
"01:38:42,0837820","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value"
"01:38:42,0838106","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,0838284","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\SafeDllSearchMode","NAME NOT FOUND","Length: 16"
"01:38:42,0842557","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFile","C:\Users\thoma\AppData\Local\Temp\MSASN1.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"01:38:42,0846693","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFile","C:\Windows\SysWOW64\msasn1.dll","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"01:38:42,0847272","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","QueryBasicInformationFile","C:\Windows\SysWOW64\msasn1.dll","SUCCESS","CreationTime: 16.10.2020 08:19:29, LastAccessTime: 28.06.2021 01:38:32, LastWriteTime: 16.10.2020 08:19:29, ChangeTime: 24.06.2021 09:04:29, FileAttributes: A"
"01:38:42,0847470","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CloseFile","C:\Windows\SysWOW64\msasn1.dll","SUCCESS",""
"01:38:42,0849889","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFile","C:\Windows\SysWOW64\msasn1.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
"01:38:42,0851043","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFileMapping","C:\Windows\SysWOW64\msasn1.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE"
"01:38:42,0851456","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\CI","REPARSE","Desired Access: Read"
"01:38:42,0851740","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\CI","SUCCESS","Desired Access: Read"
"01:38:42,0851969","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Disable26178932","NAME NOT FOUND","Length: 20"
"01:38:42,0852130","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Control\CI","SUCCESS",""
"01:38:42,0852339","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\CI","REPARSE","Desired Access: Query Value"
"01:38:42,0852507","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\CI","SUCCESS","Desired Access: Query Value"
"01:38:42,0852672","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Disable26178932","NAME NOT FOUND","Length: 80"
"01:38:42,0852849","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Control\CI","SUCCESS",""
"01:38:42,0853000","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFileMapping","C:\Windows\SysWOW64\msasn1.dll","SUCCESS","SyncType: SyncTypeOther"
"01:38:42,0854246","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Load Image","C:\Windows\SysWOW64\msasn1.dll","SUCCESS","Image Base: 0x6ea70000, Image Size: 0xe000"
"01:38:42,0855131","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CloseFile","C:\Windows\SysWOW64\msasn1.dll","SUCCESS",""
"01:38:42,0856290","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"01:38:42,0856416","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: Name"
"01:38:42,0856629","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\msasn1","NAME NOT FOUND","Desired Access: Read"
"01:38:42,0857395","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 1, Name: xxx"
"01:38:42,0857659","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0857797","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\xxx","SUCCESS","Desired Access: Read"
"01:38:42,0858027","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\xxx\Blob","BUFFER OVERFLOW","Length: 12"
"01:38:42,0858157","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\xxx\Blob","BUFFER OVERFLOW","Length: 144"
"01:38:42,0858357","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\xxx\Blob","SUCCESS","Type: REG_BINARY, Length: 1.199, Data: ..."
"01:38:42,0858578","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\xxx","SUCCESS",""
"01:38:42,0859010","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 2, Name: 18F7C1FCC3090203FD5BAA2F861A754976C8DD25"
"01:38:42,0859214","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400"
...
"01:38:42,0899293","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\xxx","SUCCESS","Desired Access: Read"
"01:38:42,0899464","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\xxx\Blob","BUFFER OVERFLOW","Length: 12"
"01:38:42,0899614","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\xxx\Blob","BUFFER OVERFLOW","Length: 144"
"01:38:42,0906571","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\xxx\Blob","SUCCESS","Type: REG_BINARY, Length: 1.071, Data: ..."
"01:38:42,0909158","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\xxx","SUCCESS",""
"01:38:42,0909549","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 21, Name: xxx"
"01:38:42,0909825","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0909975","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\xxx","SUCCESS","Desired Access: Read"
"01:38:42,0910161","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\xxx\Blob","BUFFER OVERFLOW","Length: 12"
"01:38:42,0910301","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\xxx\Blob","BUFFER OVERFLOW","Length: 144"
"01:38:42,0910533","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\xxx\Blob","SUCCESS","Type: REG_BINARY, Length: 1.059, Data: ..."
"01:38:42,0910733","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\xxx","SUCCESS",""
"01:38:42,0911053","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS",""
"01:38:42,0911305","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0911463","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS","Desired Access: Read"
"01:38:42,0911831","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,0912000","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,0912149","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS",""
"01:38:42,0912333","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0913289","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS","Desired Access: Read"
"01:38:42,0913467","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,0913604","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,0913754","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS",""
"01:38:42,0913903","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS",""
"01:38:42,0914220","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"01:38:42,0914387","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: Name"
"01:38:42,0914658","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\AuthRoot","REPARSE","Desired Access: Read"
"01:38:42,0915408","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Desired Access: Read"
"01:38:42,0915667","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,0915876","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0916004","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Desired Access: Read"
"01:38:42,0916211","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0916327","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Desired Access: Read"
"01:38:42,0916512","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 56, Values: 0"
"01:38:42,0916653","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 56, Values: 0"
"01:38:42,0916784","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 0, Name: xxx"
"01:38:42,0916996","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,0917131","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\xxx","SUCCESS","Desired Access: Read"
"01:38:42,0917381","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\xxx\Blob","BUFFER OVERFLOW","Length: 12"
"01:38:42,0917537","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\xxx\Blob","BUFFER OVERFLOW","Length: 144"
"01:38:42,0917971","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\xxx\Blob","SUCCESS","Type: REG_BINARY, Length: 1.579, Data: ..."
01:38:42,0918307","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\xxx","SUCCESS",""
...
"01:38:42,1091760","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 53, Name: xxx"
"01:38:42,1092510","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,1094109","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\xxx","SUCCESS","Desired Access: Read"
"01:38:42,1094393","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\xxx\Blob","BUFFER OVERFLOW","Length: 12"
"01:38:42,1094601","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\xxx\Blob","BUFFER OVERFLOW","Length: 144"
"01:38:42,1094751","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\xxx\Blob","SUCCESS","Type: REG_BINARY, Length: 1.502, Data: ..."
"01:38:42,1095111","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\xxx","SUCCESS",""
"01:38:42,1095968","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 54, Name: xxx"
"01:38:42,1096341","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,1096525","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\xxx","SUCCESS","Desired Access: Read"
"01:38:42,1096962","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\xxx\Blob","BUFFER OVERFLOW","Length: 12"
"01:38:42,1097212","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\xxx\Blob","BUFFER OVERFLOW","Length: 144"
"01:38:42,1097465","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\xxx\Blob","SUCCESS","Type: REG_BINARY, Length: 1.628, Data: ..."
"01:38:42,1097857","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\xxx","SUCCESS",""
"01:38:42,1098545","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 55, Name: xxx"
"01:38:42,1098902","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,1099079","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\xxx","SUCCESS","Desired Access: Read"
"01:38:42,1099414","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\xxx\Blob","BUFFER OVERFLOW","Length: 12"
"01:38:42,1099656","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\xxx\Blob","BUFFER OVERFLOW","Length: 144"
"01:38:42,1099960","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\xxx\Blob","SUCCESS","Type: REG_BINARY, Length: 1.873, Data: ...
"01:38:42,1100259","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\xxx","SUCCESS",""
"01:38:42,1100747","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS",""
"01:38:42,1101276","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,1101622","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS","Desired Access: Read"
"01:38:42,1102129","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1102382","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1102606","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS",""
"01:38:42,1102834","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,1103049","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS","Desired Access: Read"
"01:38:42,1103287","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1103616","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1103899","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS",""
"01:38:42,1104114","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS",""
"01:38:42,1104708","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"01:38:42,1105026","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: Name"
"01:38:42,1105425","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\ROOT","REPARSE","Desired Access: Read"
"01:38:42,1105757","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\ROOT","SUCCESS","Desired Access: Read"
"01:38:42,1106095","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,1106529","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,1106948","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Desired Access: Read"
"01:38:42,1107269","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1107566","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1107829","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates","SUCCESS",""
"01:38:42,1108080","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,1108263","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Desired Access: Read"
"01:38:42,1108551","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1108687","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1108863","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs","SUCCESS",""
"01:38:42,1109074","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,1109275","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Desired Access: Read"
"01:38:42,1109488","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1109762","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1109979","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs","SUCCESS",""
"01:38:42,1110158","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS",""
"01:38:42,1110527","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"01:38:42,1110710","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: Name"
"01:38:42,1111114","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\ROOT\PhysicalStores","REPARSE","Desired Access: Read"
"01:38:42,1111428","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\ROOT\PhysicalStores","NAME NOT FOUND","Desired Access: Read"
"01:38:42,1111879","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"01:38:42,1112170","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: Name"
"01:38:42,1112466","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\ROOT","REPARSE","Desired Access: Read"
"01:38:42,1112690","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\ROOT","SUCCESS","Desired Access: Read"
"01:38:42,1113075","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,1113339","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS",""
"01:38:42,1113767","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"01:38:42,1113957","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: Name"
"01:38:42,1114240","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\ROOT","REPARSE","Desired Access: Read"
"01:38:42,1114443","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\ROOT","SUCCESS","Desired Access: Read"
"01:38:42,1114759","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,1115114","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,1115273","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Desired Access: Read"
"01:38:42,1115751","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,1116068","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS","Desired Access: Read"
"01:38:42,1116547","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1116872","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1117118","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS",""
"01:38:42,1117485","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,1117645","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS","Desired Access: Read"
"01:38:42,1117888","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1118147","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1118612","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS",""
"01:38:42,1119023","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,1119335","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS","Desired Access: Read"
"01:38:42,1119581","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1119840","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1120733","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS",""
"01:38:42,1121299","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS",""
"01:38:42,1123166","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"01:38:42,1123545","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM","SUCCESS","Query: Name"
"01:38:42,1124333","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\SmartCardRoot","REPARSE","Desired Access: Read"
"01:38:42,1125022","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Desired Access: Read"
"01:38:42,1125799","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,1126277","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,1126676","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Desired Access: Read"
"01:38:42,1127361","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,1127717","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Desired Access: Read"
"01:38:42,1128080","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1128405","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1128770","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS",""
"01:38:42,1129396","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,1129872","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Desired Access: Read"
"01:38:42,1130368","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1130707","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1131148","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS",""
"01:38:42,1131441","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,1131682","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Desired Access: Read"
"01:38:42,1132163","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1132395","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1132619","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS",""
"01:38:42,1132970","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS",""
"01:38:42,1135856","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"01:38:42,1136135","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKU","SUCCESS","Query: Name"
"01:38:42,1136703","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access"
"01:38:42,1137839","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0"
"01:38:42,1138184","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKCU","SUCCESS","Query: Name"
"01:38:42,1138640","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Desired Access: Read"
"01:38:42,1139179","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetInfoKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
"01:38:42,1139790","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,1140150","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Desired Access: Read"
"01:38:42,1140615","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,1141087","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Desired Access: Read"
"01:38:42,1141455","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1141601","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1141877","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS",""
"01:38:42,1142110","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,1142405","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Desired Access: Read"
"01:38:42,1142877","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1143023","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1143172","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS",""
"01:38:42,1143366","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400"
"01:38:42,1143504","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Desired Access: Read"
"01:38:42,1143692","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1143819","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0"
"01:38:42,1143978","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS",""
"01:38:42,1144129","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS",""
"01:38:42,1144259","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKCU","SUCCESS",""
"01:38:49,7492828","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS",""
"01:38:49,7493248","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS",""
"01:38:49,7493401","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS",""
"01:38:49,7493599","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS",""
"01:38:49,7495285","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS",""
"01:38:49,7496112","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKCU\SOFTWARE\Microsoft\SystemCertificates\Root","SUCCESS",""
"01:38:49,7499669","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFile","C:\Windows\SysWOW64\kernel.appcore.dll","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"01:38:49,7499955","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","QueryBasicInformationFile","C:\Windows\SysWOW64\kernel.appcore.dll","SUCCESS","CreationTime: 16.10.2020 08:19:25, LastAccessTime: 28.06.2021 01:38:32, LastWriteTime: 16.10.2020 08:19:25, ChangeTime: 24.06.2021 09:04:29, FileAttributes: A"
"01:38:49,7500092","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CloseFile","C:\Windows\SysWOW64\kernel.appcore.dll","SUCCESS",""
"01:38:49,7501665","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFile","C:\Windows\SysWOW64\kernel.appcore.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
"01:38:49,7502427","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFileMapping","C:\Windows\SysWOW64\kernel.appcore.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE"
"01:38:49,7502790","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\CI","REPARSE","Desired Access: Read"
"01:38:49,7503025","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\CI","SUCCESS","Desired Access: Read"
"01:38:49,7503209","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Disable26178932","NAME NOT FOUND","Length: 20"
"01:38:49,7503376","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Control\CI","SUCCESS",""
"01:38:49,7503567","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\CI","REPARSE","Desired Access: Query Value"
"01:38:49,7503731","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Control\CI","SUCCESS","Desired Access: Query Value"
"01:38:49,7503891","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Disable26178932","NAME NOT FOUND","Length: 80"
"01:38:49,7504035","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Control\CI","SUCCESS",""
"01:38:49,7504194","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CreateFileMapping","C:\Windows\SysWOW64\kernel.appcore.dll","SUCCESS","SyncType: SyncTypeOther"
"01:38:49,7505433","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Load Image","C:\Windows\SysWOW64\kernel.appcore.dll","SUCCESS","Image Base: 0x73de0000, Image Size: 0xf000"
"01:38:49,7506988","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Load Image","C:\Windows\SysWOW64\msvcrt.dll","SUCCESS","Image Base: 0x76020000, Image Size: 0xbf000"
"01:38:49,7511208","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CloseFile","C:\Windows\SysWOW64\kernel.appcore.dll","SUCCESS",""
"01:38:49,7514526","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Thread Exit","","SUCCESS","Thread ID: 3692, User Time: 0.0000000, Kernel Time: 0.0000000"
"01:38:49,7514584","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Thread Exit","","SUCCESS","Thread ID: 11532, User Time: 0.0000000, Kernel Time: 0.0000000"
"01:38:49,7514608","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Thread Exit","","SUCCESS","Thread ID: 12284, User Time: 0.0000000, Kernel Time: 0.0000000"
"01:38:49,7515481","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Thread Exit","","SUCCESS","Thread ID: 5660, User Time: 0.5781250, Kernel Time: 1.2968750"
"01:38:49,7523461","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","Process Exit","","SUCCESS","Exit Status: 0, User Time: 0.5781250 seconds, Kernel Time: 1.2968750 seconds, Private Bytes: 1.196.032, Peak Private Bytes: 1.212.416, Working Set: 5.177.344, Peak Working Set: 5.181.440"
"01:38:49,7523628","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegOpenKey","HKLM\System\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-4198695647-2910091461-4277131257-1001","SUCCESS","Desired Access: All Access"
"01:38:49,7523820","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegQueryValue","HKLM\System\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-4198695647-2910091461-4277131257-1001\\Device\HarddiskVolume8\Users\thoma\AppData\Local\Temp\6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","SUCCESS","Type: REG_BINARY, Length: 24, Data: 59 A2 03 90 AD 6B D7 01 00 00 00 00 00 00 00 00"
"01:38:49,7524078","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegSetValue","HKLM\System\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-4198695647-2910091461-4277131257-1001\\Device\HarddiskVolume8\Users\thoma\AppData\Local\Temp\6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","SUCCESS","Type: REG_BINARY, Length: 24, Data: 6F 9A 9C 94 AD 6B D7 01 00 00 00 00 00 00 00 00"
"01:38:49,7525290","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-4198695647-2910091461-4277131257-1001","SUCCESS",""
"01:38:49,7525598","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CloseFile","C:\Windows","SUCCESS",""
"01:38:49,7526196","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","CloseFile","C:\Users\thoma\AppData\Local\Temp","SUCCESS",""
"01:38:49,7526805","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions","SUCCESS",""
"01:38:49,7526880","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids","SUCCESS",""
"01:38:49,7526986","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM","SUCCESS",""
"01:38:49,7527063","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Services\crypt32","SUCCESS",""
"01:38:49,7527505","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKU","SUCCESS",""
"01:38:49,7527582","6dc8e1c9-bda7-4c8a-a834-54798e89ae3b.tmp.exe","18388","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","" |