1: 2: 3: 4: 5: 6: 7: 8: 9: 10: 11: 12: 13: 14: 15: 16: 17: 18: 19: 20: 21: 22: 23: 24: 25: 26: 27: 28: 29: 30: 31: 32: 33: 34: 35: 36: 37: 38: 39: 40: 41:
| "Time of Day","Process Name","PID","Operation","Path","Result","Detail" "23:45:25,6726910","msiexec.exe","2588","Thread Create","","SUCCESS","Thread ID: 4248" "23:45:28,3917452","msiexec.exe","2588","Thread Exit","","SUCCESS","Thread ID: 2872, User Time: 0.0000000, Kernel Time: 0.0000000" "23:45:28,4067437","msiexec.exe","2588","Thread Exit","","SUCCESS","Thread ID: 3700, User Time: 0.0000000, Kernel Time: 0.0000000" "23:45:35,4419358","msiexec.exe","2588","Thread Exit","","SUCCESS","Thread ID: 892, User Time: 0.0000000, Kernel Time: 0.0000000" "23:45:35,4419670","msiexec.exe","2588","Thread Exit","","SUCCESS","Thread ID: 3748, User Time: 0.0000000, Kernel Time: 0.0000000" "23:45:35,4420537","msiexec.exe","2588","Thread Exit","","SUCCESS","Thread ID: 1888, User Time: 0.0000000, Kernel Time: 0.0000000" "23:45:35,4578891","msiexec.exe","2588","Thread Exit","","SUCCESS","Thread ID: 3492, User Time: 0.0000000, Kernel Time: 0.0000000" "23:45:35,4579080","msiexec.exe","2588","Thread Exit","","SUCCESS","Thread ID: 1240, User Time: 0.0000000, Kernel Time: 0.0000000" "23:46:14,7801011","msiexec.exe","2588","Thread Exit","","SUCCESS","Thread ID: 3140, User Time: 0.0000000, Kernel Time: 0.0000000" "23:46:32,6796474","msiexec.exe","2588","Thread Exit","","SUCCESS","Thread ID: 4892, User Time: 0.0000000, Kernel Time: 0.0000000" "23:46:32,6797279","msiexec.exe","2588","Thread Exit","","SUCCESS","Thread ID: 3368, User Time: 0.0000000, Kernel Time: 0.0000000" "23:46:34,2124619","msiexec.exe","832","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "23:46:34,2125628","msiexec.exe","832","RegOpenKey","HKLM\SOFTWARE\Microsoft\CTF\KnownClasses","NAME NOT FOUND","Desired Access: Read" "23:46:36,0683042","msiexec.exe","832","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "23:46:36,0684005","msiexec.exe","832","RegOpenKey","HKLM\SOFTWARE\Microsoft\CTF\KnownClasses","NAME NOT FOUND","Desired Access: Read" "23:46:36,0702826","msiexec.exe","832","QueryStandardInformationFile","C:\Users\xxxxx\AppData\Local\Temp\MSI4ec9f.LOG","SUCCESS","AllocationSize: 917.504, EndOfFile: 912.998, NumberOfLinks: 1, DeletePending: False, Directory: False" "23:46:36,0703393","msiexec.exe","832","SetPositionInformationFile","C:\Users\xxxxx\AppData\Local\Temp\MSI4ec9f.LOG","SUCCESS","Position: 912.998" "23:46:36,0704022","msiexec.exe","832","WriteFile","C:\Users\xxxxx\AppData\Local\Temp\MSI4ec9f.LOG","SUCCESS","Offset: 912.998, Length: 424, Priority: Normal" "23:46:36,0732240","msiexec.exe","2588","CreateFile","C:\Program Files (x86)","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: P8315\xxxxx, OpenResult: Opened" "23:46:36,0733196","msiexec.exe","2588","QueryNetworkOpenInformationFile","C:\Program Files (x86)","SUCCESS","CreationTime: 14.07.2009 04:20:08, LastAccessTime: 20.03.2013 22:32:44, LastWriteTime: 20.03.2013 22:32:44, ChangeTime: 20.03.2013 22:32:44, AllocationSize: 01.01.1601 01:00:00, EndOfFile: 01.01.1601 01:00:00, FileAttributes: RD" "23:46:36,0733718","msiexec.exe","2588","CloseFile","C:\Program Files (x86)","SUCCESS","" "23:46:36,0737340","msiexec.exe","2588","CreateFile","C:\Program Files (x86)\PovRay","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: P8315\xxxxx" "23:46:36,0739305","msiexec.exe","2588","CreateFile","C:\Program Files (x86)\PovRay","ACCESS DENIED","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0, Impersonating: P8315\xxxxx" "23:46:36,1738650","msiexec.exe","2588","CreateFile","C:\Program Files (x86)\PovRay","ACCESS DENIED","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0, Impersonating: P8315\xxxxx" "23:46:36,2738549","msiexec.exe","2588","CreateFile","C:\Program Files (x86)\PovRay","ACCESS DENIED","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0, Impersonating: P8315\xxxxx" "23:46:36,3738706","msiexec.exe","2588","CreateFile","C:\Program Files (x86)\PovRay","ACCESS DENIED","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0, Impersonating: P8315\xxxxx" "23:46:36,3742453","msiexec.exe","2588","QueryStandardInformationFile","C:\Users\xxxxx\AppData\Local\Temp\MSI4ec9f.LOG","SUCCESS","AllocationSize: 917.504, EndOfFile: 913.422, NumberOfLinks: 1, DeletePending: False, Directory: False" "23:46:36,3743060","msiexec.exe","2588","SetPositionInformationFile","C:\Users\xxxxx\AppData\Local\Temp\MSI4ec9f.LOG","SUCCESS","Position: 913.422" "23:46:36,3743672","msiexec.exe","2588","WriteFile","C:\Users\xxxxx\AppData\Local\Temp\MSI4ec9f.LOG","SUCCESS","Offset: 913.422, Length: 730, Priority: Normal" "23:46:36,3746334","msiexec.exe","832","Thread Create","","SUCCESS","Thread ID: 132" "23:46:36,3762285","msiexec.exe","832","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "23:46:36,3763079","msiexec.exe","832","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes","SUCCESS","Desired Access: Read" "23:46:36,3764099","msiexec.exe","832","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Segoe UI","NAME NOT FOUND","Length: 144" "23:46:36,3764808","msiexec.exe","832","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes","SUCCESS","" "23:46:36,3805034","msiexec.exe","832","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "23:46:36,3806205","msiexec.exe","832","RegOpenKey","HKLM\SOFTWARE\Microsoft\CTF\KnownClasses","NAME NOT FOUND","Desired Access: Read" "23:47:06,0766193","msiexec.exe","2588","Thread Create","","SUCCESS","Thread ID: 4400" "23:47:06,0768690","msiexec.exe","2588","Thread Create","","SUCCESS","Thread ID: 3968" "23:47:43,3827365","msiexec.exe","832","Thread Exit","","SUCCESS","Thread ID: 132, User Time: 0.0000000, Kernel Time: 0.0000000" "23:47:45,7438841","msiexec.exe","832","Thread Create","","SUCCESS","Thread ID: 4284" |