Hi
This is the log.
"Time of Day","Process Name","PID","Operation","Path","Result","Detail"
"7:45:52.5264270 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:45:52.5266153 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:45:52.5266795 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:45:52.5267586 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:45:52.5268463 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:45:52.5268899 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:45:52.5269340 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:45:52.5269656 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:45:52.5270480 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:45:52.5271106 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:45:52.5271938 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:45:52.5272863 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\0","SUCCESS","Type: REG_SZ, Length: 48, Data: Root\LEGACY_RASMAN\0000"
"7:45:52.5273866 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:45:52.5274371 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:45:52.5274779 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:45:52.5276302 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_RASMAN\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:45:52.5277330 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:45:52.5277651 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:45:52.5278445 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:45:52.5279059 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:45:52.5279819 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:45:52.5280610 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:45:52.5281118 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:45:52.5281674 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:45:52.5282001 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:45:52.5282794 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:45:52.5283403 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:45:52.5284174 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:45:52.5285066 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\0","SUCCESS","Type: REG_SZ, Length: 48, Data: Root\LEGACY_RASMAN\0000"
"7:45:52.5286035 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:45:52.5286502 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:45:52.5286873 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:45:52.5288340 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_RASMAN\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:45:52.5289273 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:45:52.5289605 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS","Desired Access: Read"
"7:45:52.5290376 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:45:52.5290983 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS","Desired Access: Read"
"7:45:52.5291863 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:45:52.5292670 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:45:52.5293173 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS",""
"7:45:52.5293631 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS",""
"7:45:52.5293941 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS","Desired Access: Read"
"7:45:52.5294729 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:45:52.5295318 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS","Desired Access: Read"
"7:45:52.5296075 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:45:52.5296961 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum\0","SUCCESS","Type: REG_SZ, Length: 50, Data: Root\LEGACY_TAPISRV\0000"
"7:45:52.5297925 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS",""
"7:45:52.5298402 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS",""
"7:45:52.5298891 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:45:52.5300347 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_TAPISRV\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:45:52.5301381 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:45:52.5301707 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS","Desired Access: Read"
"7:45:52.5302504 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:45:52.5303124 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS","Desired Access: Read"
"7:45:52.5303937 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:45:52.5304761 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:45:52.5305289 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS",""
"7:45:52.5305747 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS",""
"7:45:52.5306057 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS","Desired Access: Read"
"7:45:52.5306837 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:45:52.5307446 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS","Desired Access: Read"
"7:45:52.5308228 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:45:52.5309108 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\Enum\0","SUCCESS","Type: REG_SZ, Length: 46, Data: Root\LEGACY_RPCSS\0000"
"7:45:52.5310097 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS",""
"7:45:52.5310538 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS",""
"7:45:52.5311083 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:45:52.5312678 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_RPCSS\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:45:52.5313706 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:45:52.5313991 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:45:52.5314723 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS","Desired Access: Read"
"7:45:52.5315628 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:45:52.5315958 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:45:52.5316620 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\ObjectName","SUCCESS","Type: REG_SZ, Length: 56, Data: NT AUTHORITY\NetworkService"
"7:45:52.5317545 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS",""
"7:45:52.5317947 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:45:52.5318729 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\PlugPlay","SUCCESS","Desired Access: Read"
"7:45:52.5319682 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:45:52.5320025 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\PlugPlay\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:45:52.5320819 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\PlugPlay\ObjectName","SUCCESS","Type: REG_SZ, Length: 24, Data: LocalSystem"
"7:45:52.5321788 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\PlugPlay","SUCCESS",""
"7:45:52.5322118 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:45:52.5322931 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS","Desired Access: Read"
"7:45:52.5323878 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:45:52.5324230 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:45:52.5324875 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\ObjectName","SUCCESS","Type: REG_SZ, Length: 24, Data: LocalSystem"
"7:45:52.5325808 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS",""
"7:45:52.5326127 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:45:52.5326920 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:45:52.5327864 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:45:52.5328239 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:45:52.5328926 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\ObjectName","SUCCESS","Type: REG_SZ, Length: 24, Data: LocalSystem"
"7:45:52.5329867 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:46:43.4028931 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:46:43.4030032 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:46:43.4030895 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:46:43.4031747 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:46:43.4032538 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:46:43.4033108 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:46:43.4033862 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:46:43.4034203 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:46:43.4035058 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:46:43.4035681 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:46:43.4036454 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:46:43.4037368 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\0","SUCCESS","Type: REG_SZ, Length: 48, Data: Root\LEGACY_RASMAN\0000"
"7:46:43.4041746 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:46:43.4042343 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:46:43.4042765 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:46:43.4044598 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_RASMAN\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:46:43.4045629 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:46:43.4045975 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:46:43.4046802 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:46:43.4047450 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:46:43.4048235 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:46:43.4049079 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:46:43.4049624 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:46:43.4050113 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:46:43.4050423 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:46:43.4051238 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:46:43.4051867 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:46:43.4052652 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:46:43.4053786 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\0","SUCCESS","Type: REG_SZ, Length: 48, Data: Root\LEGACY_RASMAN\0000"
"7:46:43.4054811 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:46:43.4055337 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:46:43.4055756 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:46:43.4057404 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_RASMAN\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:46:43.4060231 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:46:43.4060966 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS","Desired Access: Read"
"7:46:43.4062097 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:46:43.4062740 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS","Desired Access: Read"
"7:46:43.4063653 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:46:43.4064489 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:46:43.4065073 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS",""
"7:46:43.4065550 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS",""
"7:46:43.4066154 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS","Desired Access: Read"
"7:46:43.4067025 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:46:43.4067629 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS","Desired Access: Read"
"7:46:43.4068419 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:46:43.4069302 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum\0","SUCCESS","Type: REG_SZ, Length: 50, Data: Root\LEGACY_TAPISRV\0000"
"7:46:43.4070302 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS",""
"7:46:43.4070800 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS",""
"7:46:43.4071191 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:46:43.4072923 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_TAPISRV\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:46:43.4073962 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:46:43.4074328 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS","Desired Access: Read"
"7:46:43.4075130 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:46:43.4075725 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS","Desired Access: Read"
"7:46:43.4076482 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:46:43.4077317 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:46:43.4077842 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS",""
"7:46:43.4078370 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS",""
"7:46:43.4078694 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS","Desired Access: Read"
"7:46:43.4079499 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:46:43.4080616 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS","Desired Access: Read"
"7:46:43.4081561 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:46:43.4082499 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\Enum\0","SUCCESS","Type: REG_SZ, Length: 46, Data: Root\LEGACY_RPCSS\0000"
"7:46:43.4083466 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS",""
"7:46:43.4083854 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS",""
"7:46:43.4084148 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:46:43.4085340 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_RPCSS\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:46:43.4086125 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:46:43.4086338 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:46:43.4086941 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS","Desired Access: Read"
"7:46:43.4088103 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:46:43.4088413 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:46:43.4089062 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\ObjectName","SUCCESS","Type: REG_SZ, Length: 56, Data: NT AUTHORITY\NetworkService"
"7:46:43.4089925 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS",""
"7:46:43.4090227 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:46:43.4090788 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\PlugPlay","SUCCESS","Desired Access: Read"
"7:46:43.4091531 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:46:43.4091766 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\PlugPlay\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:46:43.4092417 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\PlugPlay\ObjectName","SUCCESS","Type: REG_SZ, Length: 24, Data: LocalSystem"
"7:46:43.4093300 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\PlugPlay","SUCCESS",""
"7:46:43.4093523 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:46:43.4094129 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS","Desired Access: Read"
"7:46:43.4095185 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:46:43.4095504 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:46:43.4096166 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\ObjectName","SUCCESS","Type: REG_SZ, Length: 24, Data: LocalSystem"
"7:46:43.4097029 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS",""
"7:46:43.4097364 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:46:43.4098175 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:46:43.4099217 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:46:43.4099557 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:46:43.4100242 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\ObjectName","SUCCESS","Type: REG_SZ, Length: 24, Data: LocalSystem"
"7:46:43.4101239 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:47:04.4114202 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:47:04.4115473 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:04.4116185 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:47:04.4117138 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:04.4118085 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:47:04.4124751 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:47:04.4143689 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:47:04.4144035 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:47:04.4144856 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:04.4145463 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:47:04.4146273 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:04.4147228 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\0","SUCCESS","Type: REG_SZ, Length: 48, Data: Root\LEGACY_RASMAN\0000"
"7:47:04.4148287 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:47:04.4148832 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:47:04.4149254 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:47:04.4151061 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_RASMAN\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:47:04.4152223 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:47:04.4152614 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:47:04.4153584 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:04.4154291 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:47:04.4155157 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:04.4156025 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:47:04.4156632 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:47:04.4157165 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:47:04.4157523 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:47:04.4158517 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:04.4159230 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:47:04.4160180 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:04.4161157 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\0","SUCCESS","Type: REG_SZ, Length: 48, Data: Root\LEGACY_RASMAN\0000"
"7:47:04.4162292 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:47:04.4162834 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:47:04.4163264 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:47:04.4165007 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_RASMAN\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:47:04.4166150 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:47:04.4166560 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS","Desired Access: Read"
"7:47:04.4167535 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:04.4168242 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS","Desired Access: Read"
"7:47:04.4169139 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:04.4170167 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:47:04.4170765 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS",""
"7:47:04.4171310 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS",""
"7:47:04.4171664 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS","Desired Access: Read"
"7:47:04.4172628 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:04.4173329 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS","Desired Access: Read"
"7:47:04.4174240 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:04.4175240 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum\0","SUCCESS","Type: REG_SZ, Length: 50, Data: Root\LEGACY_TAPISRV\0000"
"7:47:04.4176332 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS",""
"7:47:04.4176883 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS",""
"7:47:04.4177305 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:47:04.4179048 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_TAPISRV\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:47:04.4180280 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:47:04.4180691 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS","Desired Access: Read"
"7:47:04.4181666 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:04.4182400 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS","Desired Access: Read"
"7:47:04.4183325 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:04.4184233 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:47:04.4184834 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS",""
"7:47:04.4185381 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS",""
"7:47:04.4185733 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS","Desired Access: Read"
"7:47:04.4186697 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:04.4187407 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS","Desired Access: Read"
"7:47:04.4188323 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:04.4189421 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\Enum\0","SUCCESS","Type: REG_SZ, Length: 46, Data: Root\LEGACY_RPCSS\0000"
"7:47:04.4190541 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS",""
"7:47:04.4191077 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS",""
"7:47:04.4191513 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:47:04.4193254 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_RPCSS\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:47:04.4194363 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:47:04.4194709 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:47:04.4195528 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS","Desired Access: Read"
"7:47:04.4196640 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:47:04.4197039 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:47:04.4197779 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\ObjectName","SUCCESS","Type: REG_SZ, Length: 56, Data: NT AUTHORITY\NetworkService"
"7:47:04.4198830 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS",""
"7:47:04.4199430 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:47:04.4200308 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\PlugPlay","SUCCESS","Desired Access: Read"
"7:47:04.4204414 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:47:04.4204939 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\PlugPlay\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:47:04.4205850 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\PlugPlay\ObjectName","SUCCESS","Type: REG_SZ, Length: 24, Data: LocalSystem"
"7:47:04.4206948 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\PlugPlay","SUCCESS",""
"7:47:04.4207345 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:47:04.4208272 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS","Desired Access: Read"
"7:47:04.4209367 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:47:04.4209764 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:47:04.4210521 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\ObjectName","SUCCESS","Type: REG_SZ, Length: 24, Data: LocalSystem"
"7:47:04.4211566 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS",""
"7:47:04.4211910 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:47:04.4212767 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:47:04.4213862 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:47:04.4214242 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:47:04.4214994 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\ObjectName","SUCCESS","Type: REG_SZ, Length: 24, Data: LocalSystem"
"7:47:04.4216053 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:47:16.5396381 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:47:16.5397546 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\ProtectedStorage","SUCCESS","Desired Access: Read"
"7:47:16.5398815 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:47:16.5399144 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:47:16.5399887 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\ProtectedStorage","SUCCESS","Desired Access: Read"
"7:47:16.5400902 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:47:16.5401315 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\ProtectedStorage\ImagePath","BUFFER OVERFLOW","Length: 12"
"7:47:16.5402120 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\ProtectedStorage\ImagePath","SUCCESS","Type: REG_EXPAND_SZ, Length: 64, Data: %SystemRoot%\system32\lsass.exe"
"7:47:16.5403078 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\ProtectedStorage","SUCCESS",""
"7:47:16.5403343 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:47:16.5404139 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\ProtectedStorage","SUCCESS","Desired Access: Read"
"7:47:16.5405095 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:47:16.5405452 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\ProtectedStorage\Type","SUCCESS","Type: REG_DWORD, Length: 4, Data: 288"
"7:47:16.5406399 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\ProtectedStorage\Start","SUCCESS","Type: REG_DWORD, Length: 4, Data: 2"
"7:47:16.5407207 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\ProtectedStorage\ErrorControl","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:16.5407953 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\ProtectedStorage\Tag","NAME NOT FOUND","Length: 16"
"7:47:16.5408576 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\ProtectedStorage\DependOnService","BUFFER OVERFLOW","Length: 12"
"7:47:16.5409210 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\ProtectedStorage\DependOnService","SUCCESS","Type: REG_MULTI_SZ, Length: 14, Data: RpcSs"
"7:47:16.5409992 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\ProtectedStorage\DependOnGroup","NAME NOT FOUND","Length: 12"
"7:47:16.5410596 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\ProtectedStorage\Group","NAME NOT FOUND","Length: 12"
"7:47:16.5411191 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\ProtectedStorage\DisplayName","BUFFER OVERFLOW","Length: 12"
"7:47:16.5411802 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\ProtectedStorage\DisplayName","SUCCESS","Type: REG_SZ, Length: 36, Data: Protected Storage"
"7:47:16.5412895 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\ProtectedStorage","SUCCESS",""
"7:47:16.5413328 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\ProtectedStorage\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:47:16.5414037 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\ProtectedStorage\ObjectName","SUCCESS","Type: REG_SZ, Length: 24, Data: LocalSystem"
"7:47:16.5415093 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\ProtectedStorage","SUCCESS",""
"7:47:25.7143654 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:47:25.7144771 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:25.7145394 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:47:25.7146246 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:25.7147096 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:47:25.7147797 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:47:25.7148277 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:47:25.7148596 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:47:25.7149504 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:25.7150129 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:47:25.7150923 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:25.7151875 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\0","SUCCESS","Type: REG_SZ, Length: 48, Data: Root\LEGACY_RASMAN\0000"
"7:47:25.7152931 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:47:25.7153532 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:47:25.7153940 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:47:25.7155770 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_RASMAN\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:47:25.7156971 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:47:25.7157468 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:47:25.7158292 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:25.7158915 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:47:25.7159678 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:25.7160505 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:47:25.7161019 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:47:25.7161477 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:47:25.7161785 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:47:25.7162539 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:25.7163117 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:47:25.7163863 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:25.7164771 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\0","SUCCESS","Type: REG_SZ, Length: 48, Data: Root\LEGACY_RASMAN\0000"
"7:47:25.7165757 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:47:25.7166229 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:47:25.7166618 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:47:25.7168146 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_RASMAN\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:47:25.7169084 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:47:25.7169417 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS","Desired Access: Read"
"7:47:25.7170196 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:25.7170788 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS","Desired Access: Read"
"7:47:25.7171534 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:25.7172342 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:47:25.7172825 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS",""
"7:47:25.7173306 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS",""
"7:47:25.7173593 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS","Desired Access: Read"
"7:47:25.7174417 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:25.7175057 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS","Desired Access: Read"
"7:47:25.7175873 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:25.7176909 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum\0","SUCCESS","Type: REG_SZ, Length: 50, Data: Root\LEGACY_TAPISRV\0000"
"7:47:25.7177960 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS",""
"7:47:25.7178424 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS",""
"7:47:25.7178820 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:47:25.7180427 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_TAPISRV\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:47:25.7181382 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:47:25.7181751 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS","Desired Access: Read"
"7:47:25.7182594 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:25.7183223 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS","Desired Access: Read"
"7:47:25.7184022 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:25.7184841 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:47:25.7185385 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS",""
"7:47:25.7185849 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS",""
"7:47:25.7186176 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS","Desired Access: Read"
"7:47:25.7187115 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:25.7187710 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS","Desired Access: Read"
"7:47:25.7188545 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:25.7189484 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\Enum\0","SUCCESS","Type: REG_SZ, Length: 46, Data: Root\LEGACY_RPCSS\0000"
"7:47:25.7190506 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS",""
"7:47:25.7190947 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS",""
"7:47:25.7191347 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:47:25.7192914 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_RPCSS\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:47:25.7193939 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:47:25.7194272 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:47:25.7195026 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS","Desired Access: Read"
"7:47:25.7195973 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:47:25.7196306 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:47:25.7197155 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\ObjectName","SUCCESS","Type: REG_SZ, Length: 56, Data: NT AUTHORITY\NetworkService"
"7:47:25.7198136 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS",""
"7:47:25.7198594 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:47:25.7199409 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\PlugPlay","SUCCESS","Desired Access: Read"
"7:47:25.7200412 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:47:25.7200773 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\PlugPlay\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:47:25.7201446 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\PlugPlay\ObjectName","SUCCESS","Type: REG_SZ, Length: 24, Data: LocalSystem"
"7:47:25.7202432 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\PlugPlay","SUCCESS",""
"7:47:25.7202781 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:47:25.7203566 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS","Desired Access: Read"
"7:47:25.7204511 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:47:25.7204851 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:47:25.7205497 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\ObjectName","SUCCESS","Type: REG_SZ, Length: 24, Data: LocalSystem"
"7:47:25.7206528 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS",""
"7:47:25.7206843 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:47:25.7207645 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:47:25.7208726 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:47:25.7209115 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:47:25.7209838 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\ObjectName","SUCCESS","Type: REG_SZ, Length: 24, Data: LocalSystem"
"7:47:25.7210833 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:47:25.7251547 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:47:25.7252849 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:25.7253531 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:47:25.7254349 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:25.7255210 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:47:25.7255819 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:47:25.7256355 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:47:25.7256688 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:47:25.7257618 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:25.7258283 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:47:25.7259087 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:25.7260093 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\0","SUCCESS","Type: REG_SZ, Length: 48, Data: Root\LEGACY_RASMAN\0000"
"7:47:25.7261121 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:47:25.7261658 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:47:25.7262091 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:47:25.7263887 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_RASMAN\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:47:25.7264976 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:47:25.7265365 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:47:25.7266222 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:25.7266865 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:47:25.7267720 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:25.7268555 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:47:25.7269212 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:47:25.7269731 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:47:25.7270050 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:47:25.7270938 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:25.7271589 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:47:25.7272430 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:25.7273366 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\0","SUCCESS","Type: REG_SZ, Length: 48, Data: Root\LEGACY_RASMAN\0000"
"7:47:25.7274422 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:47:25.7274936 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:47:25.7275366 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:47:25.7276986 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_RASMAN\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:47:25.7278101 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:47:25.7278531 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS","Desired Access: Read"
"7:47:25.7279436 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:25.7280096 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS","Desired Access: Read"
"7:47:25.7280951 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:25.7281805 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:47:25.7282359 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS",""
"7:47:25.7282833 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS",""
"7:47:25.7283138 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS","Desired Access: Read"
"7:47:25.7284010 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:25.7284655 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS","Desired Access: Read"
"7:47:25.7285404 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:25.7286292 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum\0","SUCCESS","Type: REG_SZ, Length: 50, Data: Root\LEGACY_TAPISRV\0000"
"7:47:25.7287287 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS",""
"7:47:25.7287837 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS",""
"7:47:25.7288228 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:47:25.7289818 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_TAPISRV\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:47:25.7290851 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:47:25.7291184 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS","Desired Access: Read"
"7:47:25.7291988 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:25.7292625 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS","Desired Access: Read"
"7:47:25.7293458 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:25.7294528 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:47:25.7295100 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS",""
"7:47:25.7295782 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS",""
"7:47:25.7296123 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS","Desired Access: Read"
"7:47:25.7296972 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:25.7297606 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS","Desired Access: Read"
"7:47:25.7298453 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:25.7299350 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\Enum\0","SUCCESS","Type: REG_SZ, Length: 46, Data: Root\LEGACY_RPCSS\0000"
"7:47:25.7300341 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS",""
"7:47:25.7300830 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS",""
"7:47:25.7301210 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:47:25.7302755 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_RPCSS\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:47:25.7303766 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:47:25.7304322 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:47:25.7305102 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS","Desired Access: Read"
"7:47:25.7306054 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:47:25.7306378 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:47:25.7307057 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\ObjectName","SUCCESS","Type: REG_SZ, Length: 56, Data: NT AUTHORITY\NetworkService"
"7:47:25.7308024 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS",""
"7:47:25.7308421 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:47:25.7310010 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\PlugPlay","SUCCESS","Desired Access: Read"
"7:47:25.7311119 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:47:25.7311499 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\PlugPlay\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:47:25.7312203 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\PlugPlay\ObjectName","SUCCESS","Type: REG_SZ, Length: 24, Data: LocalSystem"
"7:47:25.7313145 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\PlugPlay","SUCCESS",""
"7:47:25.7313491 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:47:25.7314363 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS","Desired Access: Read"
"7:47:25.7315332 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:47:25.7315690 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:47:25.7316343 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\ObjectName","SUCCESS","Type: REG_SZ, Length: 24, Data: LocalSystem"
"7:47:25.7317299 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS",""
"7:47:25.7317592 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:47:25.7318374 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:47:25.7319338 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:47:25.7319696 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:47:25.7320355 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\ObjectName","SUCCESS","Type: REG_SZ, Length: 24, Data: LocalSystem"
"7:47:25.7321327 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:47:28.2692474 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:47:28.2693739 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:28.2694451 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:47:28.2695248 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:28.2696111 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:47:28.2696681 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:47:28.2697200 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:47:28.2697530 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:47:28.2698402 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:28.2701095 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:47:28.2702151 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:28.2703142 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\0","SUCCESS","Type: REG_SZ, Length: 48, Data: Root\LEGACY_RASMAN\0000"
"7:47:28.2704305 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:47:28.2704844 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:47:28.2705274 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:47:28.2706984 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_RASMAN\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:47:28.2708333 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:47:28.2708747 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:47:28.2709713 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:28.2710395 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:47:28.2711283 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:28.2712152 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:47:28.2712711 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:47:28.2713264 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:47:28.2713577 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:47:28.2714381 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:28.2715013 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS","Desired Access: Read"
"7:47:28.2715764 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:28.2716672 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\Enum\0","SUCCESS","Type: REG_SZ, Length: 48, Data: Root\LEGACY_RASMAN\0000"
"7:47:28.2717697 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan\Enum","SUCCESS",""
"7:47:28.2718197 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:47:28.2718597 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:47:28.2720128 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_RASMAN\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:47:28.2721131 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:47:28.2721511 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS","Desired Access: Read"
"7:47:28.2723064 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:28.2723843 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS","Desired Access: Read"
"7:47:28.2724701 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:28.2725662 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:47:28.2726246 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS",""
"7:47:28.2727126 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS",""
"7:47:28.2727492 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS","Desired Access: Read"
"7:47:28.2728433 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:28.2729054 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS","Desired Access: Read"
"7:47:28.2729839 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:28.2730766 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum\0","SUCCESS","Type: REG_SZ, Length: 50, Data: Root\LEGACY_TAPISRV\0000"
"7:47:28.2731775 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv\Enum","SUCCESS",""
"7:47:28.2732258 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS",""
"7:47:28.2732660 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:47:28.2734244 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_TAPISRV\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:47:28.2735303 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:47:28.2735661 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS","Desired Access: Read"
"7:47:28.2736535 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:28.2737180 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS","Desired Access: Read"
"7:47:28.2737993 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:28.2738798 AM","services.exe","1772","RegQueryKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS","Query: Cached, SubKeys: 0, Values: 3"
"7:47:28.2739359 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS",""
"7:47:28.2739854 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS",""
"7:47:28.2740178 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS","Desired Access: Read"
"7:47:28.2741052 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\PlugPlayServiceType","NAME NOT FOUND","Length: 144"
"7:47:28.2741698 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS","Desired Access: Read"
"7:47:28.2742491 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\Enum\Count","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"7:47:28.2743427 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\Enum\0","SUCCESS","Type: REG_SZ, Length: 46, Data: Root\LEGACY_RPCSS\0000"
"7:47:28.2744578 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs\Enum","SUCCESS",""
"7:47:28.2745064 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS",""
"7:47:28.2745461 AM","services.exe","1772","RegOpenKey","HKCC\System\CurrentControlSet\Enum","SUCCESS","Desired Access: Query Value"
"7:47:28.2747056 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum\Root\LEGACY_RPCSS\0000","NAME NOT FOUND","Desired Access: Query Value"
"7:47:28.2748076 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Enum","SUCCESS",""
"7:47:28.2748380 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:47:28.2749123 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS","Desired Access: Read"
"7:47:28.2750051 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:47:28.2750391 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:47:28.2751059 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RpcSs\ObjectName","SUCCESS","Type: REG_SZ, Length: 56, Data: NT AUTHORITY\NetworkService"
"7:47:28.2752001 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RpcSs","SUCCESS",""
"7:47:28.2752400 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:47:28.2753143 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\PlugPlay","SUCCESS","Desired Access: Read"
"7:47:28.2754085 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:47:28.2754579 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\PlugPlay\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:47:28.2755227 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\PlugPlay\ObjectName","SUCCESS","Type: REG_SZ, Length: 24, Data: LocalSystem"
"7:47:28.2756213 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\PlugPlay","SUCCESS",""
"7:47:28.2756532 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:47:28.2757253 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS","Desired Access: Read"
"7:47:28.2758177 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:47:28.2758496 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:47:28.2759130 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\TapiSrv\ObjectName","SUCCESS","Type: REG_SZ, Length: 24, Data: LocalSystem"
"7:47:28.2760099 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\TapiSrv","SUCCESS",""
"7:47:28.2760387 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read"
"7:47:28.2761108 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS","Desired Access: Read"
"7:47:28.2762021 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS",""
"7:47:28.2762357 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\ObjectName","BUFFER OVERFLOW","Length: 12"
"7:47:28.2763010 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Services\RasMan\ObjectName","SUCCESS","Type: REG_SZ, Length: 24, Data: LocalSystem"
"7:47:28.2764089 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Services\RasMan","SUCCESS",""
"7:48:03.2519831 AM","services.exe","1772","WriteFile","C:\WINDOWS\system32\config\OSession.evt","SUCCESS","Offset: 0, Length: 4,096, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O"
"7:48:03.2650309 AM","services.exe","1772","WriteFile","C:\WINDOWS\system32\config\OSession.evt","SUCCESS","Offset: 404,348, Length: 264"
"7:48:03.2651091 AM","services.exe","1772","ReadFile","C:\WINDOWS\system32\config\OSession.evt","SUCCESS","Offset: 401,408, Length: 4,096, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O"
"7:48:03.2725078 AM","services.exe","1772","CreateFile","C:\WINDOWS\system32\config\OSession.evt","SUCCESS","Desired Access: Write Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"7:48:03.2731850 AM","services.exe","1772","SetBasicInformationFile","C:\WINDOWS\system32\config\OSession.evt","SUCCESS","CreationTime: 1/1/1601 3:00:00 AM, LastAccessTime: 1/1/1601 3:00:00 AM, LastWriteTime: 1/1/1601 3:00:00 AM, ChangeTime: 1/1/1601 3:00:00 AM, FileAttributes: AN"
"7:48:03.2736253 AM","services.exe","1772","CloseFile","C:\WINDOWS\system32\config\OSession.evt","SUCCESS",""
"7:48:03.2740021 AM","services.exe","1772","WriteFile","C:\WINDOWS\system32\config\OSession.evt","SUCCESS","Offset: 404,612, Length: 40"
"7:48:20.0958446 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Control\ComputerName","SUCCESS","Desired Access: Read"
"7:48:20.0960301 AM","services.exe","1772","RegOpenKey","HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName","SUCCESS","Desired Access: Read"
"7:48:20.0962025 AM","services.exe","1772","RegQueryValue","HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName\ComputerName","SUCCESS","Type: REG_SZ, Length: 22, Data: COMPUTER_1"
"7:48:20.0970724 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName","SUCCESS",""
"7:48:20.0971556 AM","services.exe","1772","RegCloseKey","HKLM\System\CurrentControlSet\Control\ComputerName","SUCCESS",""