| Operation |
Data |
Completion |
Time |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image
File Execution Options\ergdz.exe Access: generic
read
|
object name not found |
2764899995 |
| System info queried |
Type: BasicInformation |
success or wait |
2764901959 |
| System info queried |
Type: BasicInformation |
success or wait |
2764902963 |
| Section opened |
Access: map write and map read
and map execute Baseaddress: 7C800000 Size: F6000 Mapped to pid: own pid
Path: \KnownDlls\kernel32.dll |
success or wait |
2764906135 |
| System info queried |
Type: RangeStartInformation |
success or wait |
2764909855 |
| System info queried |
Type: BasicInformation |
success or wait |
2764909971 |
| Section created |
Access: query and map write and
map read and map execute and extend size Protection: read write
Attributes: reserve Path:
not known Type: reserve Baseaddress: not known
Entrypoint: F6FE1A00 Mapped to pid: own pid Size: 10000
|
success or wait |
2764910261 |
| System info queried |
Type: BasicInformation |
success or wait |
2765148680 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Terminal Server
Access: query value and enumerate sub key and notify
and read or execute and write and read control
|
success or wait |
2765151269 |
| Key value queried |
Path:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server Name:
TSAppCompat |
success or wait |
2765153231 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image
File Execution Options\ergdz.exe Access: generic
read
|
object name not found |
2765159129 |
| Section opened |
Access: map read Baseaddress:
00260000 Size: 15DF4 Mapped to pid: own pid Path: \NLS\NlsSectionUnicode |
success or wait |
2765159350 |
| Section opened |
Access: map read Baseaddress:
00280000 Size: 40EDC Mapped to pid: own pid Path: \NLS\NlsSectionLocale |
success or wait |
2765160832 |
| Section opened |
Access: query and map read
Baseaddress: 002D0000 Size: 40004 Mapped to pid: own pid Path:
\NLS\NlsSectionSortkey |
success or wait |
2765165415 |
| Section opened |
Access: map read Baseaddress:
00320000 Size: 5A04 Mapped to pid: own pid Path: \NLS\NlsSectionSortTbls |
success or wait |
2765166677 |
| Section opened |
Access: map read Baseaddress: not
known Size: not known Mapped to pid: own pid Path:
\NLS\NlsSectionSortkey00000409 |
object name not found |
2765168897 |
| Section opened |
Access: map read Baseaddress: not
known Size: not known Mapped to pid: own pid Path:
\NLS\NlsSectionSortkey00000409 |
object name not found |
2765169098 |
| Section opened |
Access: map write and map read
and map execute Baseaddress: 774E0000 Size: 13D000 Mapped to pid: own
pid Path: \KnownDlls\ole32.dll |
success or wait |
2765176089 |
| Section opened |
Access: map write and map read
and map execute Baseaddress: 77DD0000 Size: 9B000 Mapped to pid: own pid
Path: \KnownDlls\ADVAPI32.dll |
success or wait |
2765187477 |
| Section opened |
Access: map write and map read
and map execute Baseaddress: 77E70000 Size: 92000 Mapped to pid: own pid
Path: \KnownDlls\RPCRT4.dll |
success or wait |
2765192043 |
| Section opened |
Access: map write and map read
and map execute Baseaddress: 77FE0000 Size: 11000 Mapped to pid: own pid
Path: \KnownDlls\Secur32.dll |
success or wait |
2765196100 |
| Section opened |
Access: map write and map read
and map execute Baseaddress: 77F10000 Size: 49000 Mapped to pid: own pid
Path: \KnownDlls\GDI32.dll |
success or wait |
2765202205 |
| Section opened |
Access: map write and map read
and map execute Baseaddress: 7E410000 Size: 91000 Mapped to pid: own pid
Path: \KnownDlls\USER32.dll |
success or wait |
2765204830 |
| Section opened |
Access: map write and map read
and map execute Baseaddress: 77C10000 Size: 58000 Mapped to pid: own pid
Path: \KnownDlls\msvcrt.dll |
success or wait |
2765211164 |
| Section opened |
Access: map write and map read
and map execute Baseaddress: 77120000 Size: 8B000 Mapped to pid: own pid
Path: \KnownDlls\OLEAUT32.dll |
success or wait |
2765219505 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Terminal Server
Access: query value and enumerate sub key and notify
and read or execute and write and read control
|
success or wait |
2765228275 |
| Key value queried |
Path:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server Name:
TSAppCompat |
success or wait |
2765228741 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image
File Execution Options\Secur32.dll Access: generic
read
|
object name not found |
2765237363 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image
File Execution Options\RPCRT4.dll Access: generic
read
|
object name not found |
2765238364 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image
File Execution Options\ADVAPI32.dll Access: generic
read
|
object name not found |
2765239017 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Terminal Server
Access: query value and enumerate sub key and notify
and read or execute and write and read control
|
success or wait |
2765239417 |
| Key value queried |
Path:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server Name:
TSAppCompat |
success or wait |
2765239675 |
| Key value queried |
Path:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server Name:
TSUserEnabled |
success or wait |
2765245159 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Access: query value and enumerate sub key and
notify and read or execute and write and read
control
|
success or wait |
2765249589 |
| Key value queried |
Path:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Name: LeakTrack |
object name not found |
2765250074 |
| Key opened |
Path: HKEY_LOCAL_MACHINE Access:
maximum allowed |
success or wait |
2765250961 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Diagnostics Access: query value and enumerate sub key
and notify and read or execute and write and
read control
|
object name not found |
2765251359 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image
File Execution Options\USER32.dll Access: generic
read
|
object name not found |
2765251872 |
| System info queried |
Type: BasicInformation |
success or wait |
2765252121 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager
Access: query value and read or execute |
success or wait |
2765253744 |
| Key value queried |
Path:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager Name:
SafeDllSearchMode |
object name not found |
2765254054 |
| Section created |
Access: map write and map read
and map execute Protection: execute Attributes: commit Path: not known
Type: commit Baseaddress:
00470000 Entrypoint: F6FE1A00 Mapped to pid: own
pid Size: 1AE00
|
success or wait |
2765255365 |
| Section created |
Access: map write and map read
and map execute Protection: execute Attributes: commit Path: not known
Type: commit Baseaddress:
00470000 Entrypoint: F6FE1A00 Mapped to pid: own
pid Size: 1AE00
|
success or wait |
2765257544 |
| Section created |
Access: query and map write and
map read and map execute Protection: execute Attributes: image Path: not
known Type: image
Baseaddress: 76390000 Entrypoint: 763912C0
Mapped to pid: own pid Size: 1D000
|
success or wait |
2765259336 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option
Access: query value and set value and read or execute
and write
|
object name not found |
2765260686 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Access: query value and read or execute |
success or wait |
2765260910 |
| Key value queried |
Path:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Name: TransparentEnabled |
success or wait |
2765261354 |
| Key opened |
Path:
HKEY_USERS\S-1-5-21-220523388-1935655697-1343024091-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Access:
query value and read or execute
|
object name not found |
2765262646 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image
File Execution Options\IMM32.DLL Access: generic
read
|
object name not found |
2765266850 |
| System info queried |
Type: BasicInformation |
success or wait |
2765266996 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image
File Execution Options\ntdll.dll Access: generic
read
|
object name not found |
2765268062 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image
File Execution Options\kernel32.dll Access: generic
read
|
object name not found |
2765268295 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image
File Execution Options\GDI32.dll Access: generic
read
|
object name not found |
2765268572 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image
File Execution Options\msvcrt.dll Access: generic
read
|
object name not found |
2765269108 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image
File Execution Options\ole32.dll Access: generic
read
|
object name not found |
2765269333 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image
File Execution Options\OLEAUT32.dll Access: generic
read
|
object name not found |
2765269688 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Error Message
Instrument\ Access: query value and enumerate sub
key and notify and read or execute and write and
read control
|
object name not found |
2765270211 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\GRE_Initialize Access: query value and enumerate sub
key and notify and read or execute and write and
read control
|
success or wait |
2765270630 |
| Key value queried |
Path:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\GRE_Initialize Name: DisableMetaFiles |
object name not found |
2765270914 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows
Access: query value and enumerate sub key and
notify and read or execute and write and read
control
|
success or wait |
2765275120 |
| Key value queried |
Path:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
Name: AppInit_DLLs |
success or wait |
2765275378 |
| System info queried |
Type: BasicInformation |
success or wait |
2765278062 |
| Section opened |
Access: map read Baseaddress:
008B0000 Size: 20C2 Mapped to pid: own pid Path: \NLS\NlsSectionCType |
success or wait |
2765279720 |
| System info queried |
Type: BasicInformation |
success or wait |
2765290862 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2765291048 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager
Access: query value and enumerate sub key and notify
and read or execute and write and read control
|
success or wait |
2765300076 |
| Key value queried |
Path:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager Name:
CriticalSectionTimeout |
success or wait |
2765301194 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\Software\Microsoft\Ole Access: query value and
enumerate sub key and notify and read or execute and
write and read control
|
success or wait |
2765306405 |
| Key value queried |
Path:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole Name: RWLockResourceTimeOut |
object name not found |
2765306884 |
| System info queried |
Type: BasicInformation |
success or wait |
2765314167 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2765314361 |
| System info queried |
Type: BasicInformation |
success or wait |
2765314597 |
| System info queried |
Type: ProcessorInformation |
success or wait |
2765315200 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\Software\Classes\Interface Access: query value and
enumerate sub key and notify and read or execute
and write and read control
|
success or wait |
2765315415 |
| Key value queried |
Path:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface Name:
InterfaceHelperDisableAll |
object name not found |
2765315737 |
| Key value queried |
Path:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface Name:
InterfaceHelperDisableAllForOle32 |
object name not found |
2765316915 |
| Key value queried |
Path:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface Name:
InterfaceHelperDisableTypeLib |
object name not found |
2765317085 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{00020400-0000-0000-C000-000000000046}
Access: query value and enumerate
sub key and notify and read or execute and write
and read control
|
success or wait |
2765318521 |
| Key value queried |
Path:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00020400-0000-0000-C000-000000000046}
Name: InterfaceHelperDisableAll |
object name not found |
2765318840 |
| Key value queried |
Path:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00020400-0000-0000-C000-000000000046}
Name: InterfaceHelperDisableAllForOle32 |
object name not found |
2765319008 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT Access: query value and
read or execute |
object name not found |
2765325142 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT\UserEra Access: query value
and enumerate sub key and read or execute |
object name not found |
2765326185 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT Access: query value and
read or execute |
object name not found |
2765327968 |
| System info queried |
Type: BasicInformation |
success or wait |
2765331024 |
| Process terminated |
Path: own process file path PID:
own pid Cmdline: own process cmdline |
success or wait |
2765364999 |
| Key opened |
Path:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\GRE_Initialize Access: query value and enumerate sub
key and notify and read or execute and write and
read control
|
success or wait |
2765366449 |
| Key value queried |
Path:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\GRE_Initialize Name: DisableMetaFiles |
object name not found |
2765366785 |
| Process terminated |
Path: own process file path PID:
own pid Cmdline: own process cmdline |
NOSTATUS |
2765368806 |