"Time of Day","Process Name","PID","Operation","Path","Result","Detail" "18:31:51.1765894","hpzwup01.exe","3936","RegCreateKey","HKLM\Software\Microsoft\Tracing","SUCCESS","Desired Access: All Access" "18:31:51.2525583","hpzwup01.exe","3936","RegCreateKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon","SUCCESS","Desired Access: Read/Write" "18:31:51.3332023","hpzwup01.exe","3936","RegCreateKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon","SUCCESS","Desired Access: Read/Write" "18:31:57.0771477","hpzwup01.exe","3936","RegCreateKey","HKCR\AppID\{11BC7FC2-0F43-4226-B89B-30B06D81002E}","SUCCESS","Desired Access: Read/Write" "18:31:57.0839676","hpzwup01.exe","3936","RegSetValue","HKCR\AppID\{11BC7FC2-0F43-4226-B89B-30B06D81002E}\(Default)","SUCCESS","Type: REG_SZ, Length: 32, Data: HPCommunication" "18:31:57.0861154","hpzwup01.exe","3936","RegCreateKey","HKCR\AppID\HPCommunication.DLL","SUCCESS","Desired Access: Read/Write" "18:31:57.0872468","hpzwup01.exe","3936","RegSetValue","HKCR\AppID\HPCommunication.DLL\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {11BC7FC2-0F43-4226-B89B-30B06D81002E}" "18:31:57.1079008","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.HPObjectInstaller.1","SUCCESS","Desired Access: Read/Write" "18:31:57.1100935","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.HPObjectInstaller.1\(Default)","SUCCESS","Type: REG_SZ, Length: 48, Data: HPObjectInstaller Class" "18:31:57.1109110","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.HPObjectInstaller.1\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.1115314","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.HPObjectInstaller.1\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}" "18:31:57.1130682","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.HPObjectInstaller","SUCCESS","Desired Access: Read/Write" "18:31:57.1134579","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.HPObjectInstaller\(Default)","SUCCESS","Type: REG_SZ, Length: 48, Data: HPObjectInstaller Class" "18:31:57.1158155","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.HPObjectInstaller\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.1162323","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.HPObjectInstaller\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}" "18:31:57.1168992","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.HPObjectInstaller\CurVer","SUCCESS","Desired Access: Read/Write" "18:31:57.1187094","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.HPObjectInstaller\CurVer\(Default)","SUCCESS","Type: REG_SZ, Length: 72, Data: HPCommunication.HPObjectInstaller.1" "18:31:57.1207725","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}","SUCCESS","Desired Access: Read/Write" "18:31:57.1230807","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\(Default)","SUCCESS","Type: REG_SZ, Length: 48, Data: HPObjectInstaller Class" "18:31:57.1243272","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\ProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.1252047","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\ProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 72, Data: HPCommunication.HPObjectInstaller.1" "18:31:57.1260213","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\VersionIndependentProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.1268658","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\VersionIndependentProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 68, Data: HPCommunication.HPObjectInstaller" "18:31:57.1286140","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\Programmable","SUCCESS","Desired Access: Read/Write" "18:31:57.1300349","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\InprocServer32","SUCCESS","Desired Access: Read/Write" "18:31:57.1304520","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\InprocServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 58, Data: D:\setup\HPCommunication.dll" "18:31:57.1315337","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\InprocServer32\ThreadingModel","SUCCESS","Type: REG_SZ, Length: 20, Data: Apartment" "18:31:57.1343005","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {11BC7FC2-0F43-4226-B89B-30B06D81002E}" "18:31:57.1356485","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\TypeLib","SUCCESS","Desired Access: Read/Write" "18:31:57.1362561","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {5656DD74-990F-41E8-BBB2-3D28CF936BA4}" "18:31:57.1576161","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}","SUCCESS","Desired Access: Write" "18:31:57.1578585","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\Implemented Categories","SUCCESS","Desired Access: Write" "18:31:57.1583198","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","Desired Access: Write" "18:31:57.1596389","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}","SUCCESS","Desired Access: Write" "18:31:57.1598135","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\Implemented Categories","SUCCESS","Desired Access: Write" "18:31:57.1599638","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","Desired Access: Write" "18:31:57.1648036","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.VersionInfo.1","SUCCESS","Desired Access: Read/Write" "18:31:57.1652008","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.VersionInfo.1\(Default)","SUCCESS","Type: REG_SZ, Length: 36, Data: VersionInfo Class" "18:31:57.1688991","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.VersionInfo.1\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.1703140","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.VersionInfo.1\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {FDAD9D00-18C0-4578-9305-D711951FDF00}" "18:31:57.1718285","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.VersionInfo","SUCCESS","Desired Access: Read/Write" "18:31:57.1722188","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.VersionInfo\(Default)","SUCCESS","Type: REG_SZ, Length: 36, Data: VersionInfo Class" "18:31:57.1736052","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.VersionInfo\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.1740930","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.VersionInfo\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {FDAD9D00-18C0-4578-9305-D711951FDF00}" "18:31:57.1866952","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.VersionInfo\CurVer","SUCCESS","Desired Access: Read/Write" "18:31:57.1872849","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.VersionInfo\CurVer\(Default)","SUCCESS","Type: REG_SZ, Length: 60, Data: HPCommunication.VersionInfo.1" "18:31:57.1882219","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{FDAD9D00-18C0-4578-9305-D711951FDF00}","SUCCESS","Desired Access: Read/Write" "18:31:57.1892782","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{FDAD9D00-18C0-4578-9305-D711951FDF00}\(Default)","SUCCESS","Type: REG_SZ, Length: 36, Data: VersionInfo Class" "18:31:57.1908742","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{FDAD9D00-18C0-4578-9305-D711951FDF00}\ProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.1913620","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{FDAD9D00-18C0-4578-9305-D711951FDF00}\ProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 60, Data: HPCommunication.VersionInfo.1" "18:31:57.1921366","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{FDAD9D00-18C0-4578-9305-D711951FDF00}\VersionIndependentProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.1927932","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{FDAD9D00-18C0-4578-9305-D711951FDF00}\VersionIndependentProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 56, Data: HPCommunication.VersionInfo" "18:31:57.1943068","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{FDAD9D00-18C0-4578-9305-D711951FDF00}\Programmable","SUCCESS","Desired Access: Read/Write" "18:31:57.1951569","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{FDAD9D00-18C0-4578-9305-D711951FDF00}\InprocServer32","SUCCESS","Desired Access: Read/Write" "18:31:57.1955837","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{FDAD9D00-18C0-4578-9305-D711951FDF00}\InprocServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 58, Data: D:\setup\HPCommunication.dll" "18:31:57.1968565","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{FDAD9D00-18C0-4578-9305-D711951FDF00}\InprocServer32\ThreadingModel","SUCCESS","Type: REG_SZ, Length: 20, Data: Apartment" "18:31:57.1975231","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{FDAD9D00-18C0-4578-9305-D711951FDF00}\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {11BC7FC2-0F43-4226-B89B-30B06D81002E}" "18:31:57.2005768","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{FDAD9D00-18C0-4578-9305-D711951FDF00}\TypeLib","SUCCESS","Desired Access: Read/Write" "18:31:57.2011568","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{FDAD9D00-18C0-4578-9305-D711951FDF00}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {5656DD74-990F-41E8-BBB2-3D28CF936BA4}" "18:31:57.2065603","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.Status.1","SUCCESS","Desired Access: Read/Write" "18:31:57.2069681","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.Status.1\(Default)","SUCCESS","Type: REG_SZ, Length: 26, Data: Status Class" "18:31:57.2076856","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.Status.1\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.2089067","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.Status.1\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {D9406D30-E93B-4EB5-97BA-4DE352A5C22E}" "18:31:57.2102088","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.Status","SUCCESS","Desired Access: Read/Write" "18:31:57.2106334","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.Status\(Default)","SUCCESS","Type: REG_SZ, Length: 26, Data: Status Class" "18:31:57.2120006","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.Status\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.2125451","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.Status\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {D9406D30-E93B-4EB5-97BA-4DE352A5C22E}" "18:31:57.2138215","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.Status\CurVer","SUCCESS","Desired Access: Read/Write" "18:31:57.2143937","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.Status\CurVer\(Default)","SUCCESS","Type: REG_SZ, Length: 50, Data: HPCommunication.Status.1" "18:31:57.2162238","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}","SUCCESS","Desired Access: Read/Write" "18:31:57.2166216","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\(Default)","SUCCESS","Type: REG_SZ, Length: 26, Data: Status Class" "18:31:57.2187867","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\ProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.2193728","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\ProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 50, Data: HPCommunication.Status.1" "18:31:57.2207484","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\VersionIndependentProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.2213451","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\VersionIndependentProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 46, Data: HPCommunication.Status" "18:31:57.2222248","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\Programmable","SUCCESS","Desired Access: Read/Write" "18:31:57.2231244","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\InprocServer32","SUCCESS","Desired Access: Read/Write" "18:31:57.2235272","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\InprocServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 58, Data: D:\setup\HPCommunication.dll" "18:31:57.2262357","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\InprocServer32\ThreadingModel","SUCCESS","Type: REG_SZ, Length: 20, Data: Apartment" "18:31:57.2269291","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {11BC7FC2-0F43-4226-B89B-30B06D81002E}" "18:31:57.2278233","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\TypeLib","SUCCESS","Desired Access: Read/Write" "18:31:57.2284192","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {5656DD74-990F-41E8-BBB2-3D28CF936BA4}" "18:31:57.2292291","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}","SUCCESS","Desired Access: Write" "18:31:57.2294403","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\Implemented Categories","SUCCESS","Desired Access: Write" "18:31:57.2300373","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","Desired Access: Write" "18:31:57.2312908","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}","SUCCESS","Desired Access: Write" "18:31:57.2314576","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\Implemented Categories","SUCCESS","Desired Access: Write" "18:31:57.2317481","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","Desired Access: Write" "18:31:57.2365803","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.HPInternet.1","SUCCESS","Desired Access: Read/Write" "18:31:57.2369172","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.HPInternet.1\(Default)","SUCCESS","Type: REG_SZ, Length: 34, Data: HPInternet Class" "18:31:57.2376313","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.HPInternet.1\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.2381157","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.HPInternet.1\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {7B72AF68-E985-4136-A325-D1BC8326DFE4}" "18:31:57.2394362","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.HPInternet","SUCCESS","Desired Access: Read/Write" "18:31:57.2397687","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.HPInternet\(Default)","SUCCESS","Type: REG_SZ, Length: 34, Data: HPInternet Class" "18:31:57.2413030","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.HPInternet\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.2424023","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.HPInternet\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {7B72AF68-E985-4136-A325-D1BC8326DFE4}" "18:31:57.2436281","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.HPInternet\CurVer","SUCCESS","Desired Access: Read/Write" "18:31:57.2440879","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.HPInternet\CurVer\(Default)","SUCCESS","Type: REG_SZ, Length: 58, Data: HPCommunication.HPInternet.1" "18:31:57.2449288","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}","SUCCESS","Desired Access: Read/Write" "18:31:57.2452406","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}\(Default)","SUCCESS","Type: REG_SZ, Length: 34, Data: HPInternet Class" "18:31:57.2468657","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}\ProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.2475959","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}\ProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 58, Data: HPCommunication.HPInternet.1" "18:31:57.2648624","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}\VersionIndependentProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.2654513","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}\VersionIndependentProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 54, Data: HPCommunication.HPInternet" "18:31:57.2670881","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}\Programmable","SUCCESS","Desired Access: Read/Write" "18:31:57.2678105","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}\InprocServer32","SUCCESS","Desired Access: Read/Write" "18:31:57.2682058","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}\InprocServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 58, Data: D:\setup\HPCommunication.dll" "18:31:57.2688017","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}\InprocServer32\ThreadingModel","SUCCESS","Type: REG_SZ, Length: 20, Data: Apartment" "18:31:57.2695683","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {11BC7FC2-0F43-4226-B89B-30B06D81002E}" "18:31:57.2704536","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}\TypeLib","SUCCESS","Desired Access: Read/Write" "18:31:57.2710601","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {5656DD74-990F-41E8-BBB2-3D28CF936BA4}" "18:31:57.2718851","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}","SUCCESS","Desired Access: Write" "18:31:57.2720510","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}\Implemented Categories","SUCCESS","Desired Access: Write" "18:31:57.2723977","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","Desired Access: Write" "18:31:57.2869615","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.Settings.1","SUCCESS","Desired Access: Read/Write" "18:31:57.2874275","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.Settings.1\(Default)","SUCCESS","Type: REG_SZ, Length: 30, Data: Settings Class" "18:31:57.2881634","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.Settings.1\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.2887565","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.Settings.1\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {29A296F0-F0B9-4A6F-A9BE-F647A394849F}" "18:31:57.2902793","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.Settings","SUCCESS","Desired Access: Read/Write" "18:31:57.2906472","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.Settings\(Default)","SUCCESS","Type: REG_SZ, Length: 30, Data: Settings Class" "18:31:57.2932962","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.Settings\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.2947547","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.Settings\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {29A296F0-F0B9-4A6F-A9BE-F647A394849F}" "18:31:57.2954665","hpzwup01.exe","3936","RegCreateKey","HKCR\HPCommunication.Settings\CurVer","SUCCESS","Desired Access: Read/Write" "18:31:57.2963136","hpzwup01.exe","3936","RegSetValue","HKCR\HPCommunication.Settings\CurVer\(Default)","SUCCESS","Type: REG_SZ, Length: 54, Data: HPCommunication.Settings.1" "18:31:57.2973933","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}","SUCCESS","Desired Access: Read/Write" "18:31:57.2985569","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\(Default)","SUCCESS","Type: REG_SZ, Length: 30, Data: Settings Class" "18:31:57.2998341","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\ProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.3004172","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\ProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 54, Data: HPCommunication.Settings.1" "18:31:57.3017509","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\VersionIndependentProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.3022671","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\VersionIndependentProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 50, Data: HPCommunication.Settings" "18:31:57.3043341","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\Programmable","SUCCESS","Desired Access: Read/Write" "18:31:57.3049915","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\InprocServer32","SUCCESS","Desired Access: Read/Write" "18:31:57.3053454","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\InprocServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 58, Data: D:\setup\HPCommunication.dll" "18:31:57.3065540","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\InprocServer32\ThreadingModel","SUCCESS","Type: REG_SZ, Length: 20, Data: Apartment" "18:31:57.3070317","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {11BC7FC2-0F43-4226-B89B-30B06D81002E}" "18:31:57.3075963","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\TypeLib","SUCCESS","Desired Access: Read/Write" "18:31:57.3079720","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {5656DD74-990F-41E8-BBB2-3D28CF936BA4}" "18:31:57.3085665","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}","SUCCESS","Desired Access: Write" "18:31:57.3087322","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\Implemented Categories","SUCCESS","Desired Access: Write" "18:31:57.3090135","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","Desired Access: Write" "18:31:57.3093655","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}","SUCCESS","Desired Access: Write" "18:31:57.3095264","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\Implemented Categories","SUCCESS","Desired Access: Write" "18:31:57.3111702","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","Desired Access: Write" "18:31:57.3237383","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{5656DD74-990F-41E8-BBB2-3D28CF936BA4}","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.3257858","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{5656DD74-990F-41E8-BBB2-3D28CF936BA4}\1.0","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.3261914","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{5656DD74-990F-41E8-BBB2-3D28CF936BA4}\1.0\(Default)","SUCCESS","Type: REG_SZ, Length: 66, Data: HPCommunication 1.0 Type Library" "18:31:57.3266565","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{5656DD74-990F-41E8-BBB2-3D28CF936BA4}\1.0\FLAGS","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.3270574","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{5656DD74-990F-41E8-BBB2-3D28CF936BA4}\1.0\FLAGS\(Default)","SUCCESS","Type: REG_SZ, Length: 4, Data: 0" "18:31:57.3274857","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{5656DD74-990F-41E8-BBB2-3D28CF936BA4}\1.0\0","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.3279232","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{5656DD74-990F-41E8-BBB2-3D28CF936BA4}\1.0\0\win32","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.3284746","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{5656DD74-990F-41E8-BBB2-3D28CF936BA4}\1.0\0\win32\(Default)","SUCCESS","Type: REG_SZ, Length: 58, Data: D:\setup\HPCommunication.dll" "18:31:57.3287859","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{5656DD74-990F-41E8-BBB2-3D28CF936BA4}\1.0\HELPDIR","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.3292183","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{5656DD74-990F-41E8-BBB2-3D28CF936BA4}\1.0\HELPDIR\(Default)","SUCCESS","Type: REG_SZ, Length: 20, Data: D:\setup\" "18:31:57.3298120","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{AC823880-A980-4254-9DDA-B76BC372EAEA}","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.3641714","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{AC823880-A980-4254-9DDA-B76BC372EAEA}\(Default)","SUCCESS","Type: REG_SZ, Length: 38, Data: _IHPInternetEvents" "18:31:57.3645857","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{AC823880-A980-4254-9DDA-B76BC372EAEA}\ProxyStubClsid","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.3650265","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{AC823880-A980-4254-9DDA-B76BC372EAEA}\ProxyStubClsid\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020420-0000-0000-C000-000000000046}" "18:31:57.3653961","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{AC823880-A980-4254-9DDA-B76BC372EAEA}\ProxyStubClsid32","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.3670597","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{AC823880-A980-4254-9DDA-B76BC372EAEA}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020420-0000-0000-C000-000000000046}" "18:31:57.3674835","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{AC823880-A980-4254-9DDA-B76BC372EAEA}\TypeLib","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.3680288","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{AC823880-A980-4254-9DDA-B76BC372EAEA}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {5656DD74-990F-41E8-BBB2-3D28CF936BA4}" "18:31:57.3683621","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{AC823880-A980-4254-9DDA-B76BC372EAEA}\TypeLib\Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:57.3707099","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{CF0C7C80-6436-4CE0-AA17-7C8854DAB851}","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.3718098","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{CF0C7C80-6436-4CE0-AA17-7C8854DAB851}\(Default)","SUCCESS","Type: REG_SZ, Length: 24, Data: IHPInternet" "18:31:57.3736751","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{CF0C7C80-6436-4CE0-AA17-7C8854DAB851}\ProxyStubClsid","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.3743852","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{CF0C7C80-6436-4CE0-AA17-7C8854DAB851}\ProxyStubClsid\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:57.3747545","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{CF0C7C80-6436-4CE0-AA17-7C8854DAB851}\ProxyStubClsid32","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.3752529","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{CF0C7C80-6436-4CE0-AA17-7C8854DAB851}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:57.3756664","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{CF0C7C80-6436-4CE0-AA17-7C8854DAB851}\TypeLib","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.3762321","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{CF0C7C80-6436-4CE0-AA17-7C8854DAB851}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {5656DD74-990F-41E8-BBB2-3D28CF936BA4}" "18:31:57.3765648","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{CF0C7C80-6436-4CE0-AA17-7C8854DAB851}\TypeLib\Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:57.3779471","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{E2CEDDD6-8597-464B-86FA-96B2001E5D9D}","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.3875788","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{E2CEDDD6-8597-464B-86FA-96B2001E5D9D}\(Default)","SUCCESS","Type: REG_SZ, Length: 20, Data: ISettings" "18:31:57.3887748","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{E2CEDDD6-8597-464B-86FA-96B2001E5D9D}\ProxyStubClsid","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.3891681","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{E2CEDDD6-8597-464B-86FA-96B2001E5D9D}\ProxyStubClsid\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:57.3895472","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{E2CEDDD6-8597-464B-86FA-96B2001E5D9D}\ProxyStubClsid32","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.3899786","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{E2CEDDD6-8597-464B-86FA-96B2001E5D9D}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:57.3903247","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{E2CEDDD6-8597-464B-86FA-96B2001E5D9D}\TypeLib","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.3907518","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{E2CEDDD6-8597-464B-86FA-96B2001E5D9D}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {5656DD74-990F-41E8-BBB2-3D28CF936BA4}" "18:31:57.3910748","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{E2CEDDD6-8597-464B-86FA-96B2001E5D9D}\TypeLib\Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:57.3915843","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{C43FA267-76BC-4541-BD61-25354CDE8BEF}","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.3919570","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{C43FA267-76BC-4541-BD61-25354CDE8BEF}\(Default)","SUCCESS","Type: REG_SZ, Length: 16, Data: IStatus" "18:31:57.3923297","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{C43FA267-76BC-4541-BD61-25354CDE8BEF}\ProxyStubClsid","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.3926702","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{C43FA267-76BC-4541-BD61-25354CDE8BEF}\ProxyStubClsid\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:57.3930063","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{C43FA267-76BC-4541-BD61-25354CDE8BEF}\ProxyStubClsid32","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.3934617","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{C43FA267-76BC-4541-BD61-25354CDE8BEF}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:57.3938472","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{C43FA267-76BC-4541-BD61-25354CDE8BEF}\TypeLib","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.3942947","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{C43FA267-76BC-4541-BD61-25354CDE8BEF}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {5656DD74-990F-41E8-BBB2-3D28CF936BA4}" "18:31:57.3946250","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{C43FA267-76BC-4541-BD61-25354CDE8BEF}\TypeLib\Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:57.3951225","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{AB19FFEE-58E6-4D42-98BC-962631B59FEA}","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.4016761","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{AB19FFEE-58E6-4D42-98BC-962631B59FEA}\(Default)","SUCCESS","Type: REG_SZ, Length: 52, Data: _IHPObjectInstallerEvents" "18:31:57.4019868","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{AB19FFEE-58E6-4D42-98BC-962631B59FEA}\ProxyStubClsid","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.4023617","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{AB19FFEE-58E6-4D42-98BC-962631B59FEA}\ProxyStubClsid\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020420-0000-0000-C000-000000000046}" "18:31:57.4028341","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{AB19FFEE-58E6-4D42-98BC-962631B59FEA}\ProxyStubClsid32","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.4033059","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{AB19FFEE-58E6-4D42-98BC-962631B59FEA}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020420-0000-0000-C000-000000000046}" "18:31:57.4053780","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{AB19FFEE-58E6-4D42-98BC-962631B59FEA}\TypeLib","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.4060669","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{AB19FFEE-58E6-4D42-98BC-962631B59FEA}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {5656DD74-990F-41E8-BBB2-3D28CF936BA4}" "18:31:57.4063753","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{AB19FFEE-58E6-4D42-98BC-962631B59FEA}\TypeLib\Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:57.4069408","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{F152DBC9-CC75-414A-98CF-4B2E0D200D17}","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.4080381","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{F152DBC9-CC75-414A-98CF-4B2E0D200D17}\(Default)","SUCCESS","Type: REG_SZ, Length: 38, Data: IHPObjectInstaller" "18:31:57.4083521","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{F152DBC9-CC75-414A-98CF-4B2E0D200D17}\ProxyStubClsid","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.4087242","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{F152DBC9-CC75-414A-98CF-4B2E0D200D17}\ProxyStubClsid\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:57.4090673","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{F152DBC9-CC75-414A-98CF-4B2E0D200D17}\ProxyStubClsid32","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.4105303","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{F152DBC9-CC75-414A-98CF-4B2E0D200D17}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:57.4108991","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{F152DBC9-CC75-414A-98CF-4B2E0D200D17}\TypeLib","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.4113254","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{F152DBC9-CC75-414A-98CF-4B2E0D200D17}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {5656DD74-990F-41E8-BBB2-3D28CF936BA4}" "18:31:57.4116894","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{F152DBC9-CC75-414A-98CF-4B2E0D200D17}\TypeLib\Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:57.4122481","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{F2D9F02A-20E9-44C2-953D-33535D7C54D8}","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.4126778","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{F2D9F02A-20E9-44C2-953D-33535D7C54D8}\(Default)","SUCCESS","Type: REG_SZ, Length: 26, Data: IVersionInfo" "18:31:57.4130069","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{F2D9F02A-20E9-44C2-953D-33535D7C54D8}\ProxyStubClsid","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.4134128","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{F2D9F02A-20E9-44C2-953D-33535D7C54D8}\ProxyStubClsid\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:57.4137738","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{F2D9F02A-20E9-44C2-953D-33535D7C54D8}\ProxyStubClsid32","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.4142585","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{F2D9F02A-20E9-44C2-953D-33535D7C54D8}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:57.4146728","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{F2D9F02A-20E9-44C2-953D-33535D7C54D8}\TypeLib","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.4151633","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{F2D9F02A-20E9-44C2-953D-33535D7C54D8}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {5656DD74-990F-41E8-BBB2-3D28CF936BA4}" "18:31:57.4155114","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{F2D9F02A-20E9-44C2-953D-33535D7C54D8}\TypeLib\Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:57.4315967","hpzwup01.exe","3936","RegCreateKey","HKCR\AppID\{C0359F8F-FC4F-4292-A4B3-C3B3C60DE57B}","SUCCESS","Desired Access: Read/Write" "18:31:57.4319769","hpzwup01.exe","3936","RegSetValue","HKCR\AppID\{C0359F8F-FC4F-4292-A4B3-C3B3C60DE57B}\(Default)","SUCCESS","Type: REG_SZ, Length: 24, Data: HPScripting" "18:31:57.4324323","hpzwup01.exe","3936","RegCreateKey","HKCR\AppID\HPScripting.DLL","SUCCESS","Desired Access: Read/Write" "18:31:57.4327390","hpzwup01.exe","3936","RegSetValue","HKCR\AppID\HPScripting.DLL\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {C0359F8F-FC4F-4292-A4B3-C3B3C60DE57B}" "18:31:57.4369069","hpzwup01.exe","3936","RegCreateKey","HKCR\HPScripting.HPScript.1","SUCCESS","Desired Access: Read/Write" "18:31:57.4372591","hpzwup01.exe","3936","RegSetValue","HKCR\HPScripting.HPScript.1\(Default)","SUCCESS","Type: REG_SZ, Length: 30, Data: HPScript Class" "18:31:57.4376849","hpzwup01.exe","3936","RegCreateKey","HKCR\HPScripting.HPScript.1\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.4380562","hpzwup01.exe","3936","RegSetValue","HKCR\HPScripting.HPScript.1\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}" "18:31:57.4384777","hpzwup01.exe","3936","RegCreateKey","HKCR\HPScripting.HPScript","SUCCESS","Desired Access: Read/Write" "18:31:57.4387655","hpzwup01.exe","3936","RegSetValue","HKCR\HPScripting.HPScript\(Default)","SUCCESS","Type: REG_SZ, Length: 30, Data: HPScript Class" "18:31:57.4394921","hpzwup01.exe","3936","RegCreateKey","HKCR\HPScripting.HPScript\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.4398299","hpzwup01.exe","3936","RegSetValue","HKCR\HPScripting.HPScript\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}" "18:31:57.4402344","hpzwup01.exe","3936","RegCreateKey","HKCR\HPScripting.HPScript\CurVer","SUCCESS","Desired Access: Read/Write" "18:31:57.4405950","hpzwup01.exe","3936","RegSetValue","HKCR\HPScripting.HPScript\CurVer\(Default)","SUCCESS","Type: REG_SZ, Length: 46, Data: HPScripting.HPScript.1" "18:31:57.4412200","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}","SUCCESS","Desired Access: Read/Write" "18:31:57.4425171","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}\(Default)","SUCCESS","Type: REG_SZ, Length: 30, Data: HPScript Class" "18:31:57.4429613","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}\ProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.4432306","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}\ProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 46, Data: HPScripting.HPScript.1" "18:31:57.4437424","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}\VersionIndependentProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.4441296","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}\VersionIndependentProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 42, Data: HPScripting.HPScript" "18:31:57.4447316","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}\Programmable","SUCCESS","Desired Access: Read/Write" "18:31:57.4454390","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}\InprocServer32","SUCCESS","Desired Access: Read/Write" "18:31:57.4457382","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}\InprocServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 50, Data: D:\setup\HPScripting.dll" "18:31:57.4459943","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}\InprocServer32\ThreadingModel","SUCCESS","Type: REG_SZ, Length: 10, Data: Both" "18:31:57.4463751","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {C0359F8F-FC4F-4292-A4B3-C3B3C60DE57B}" "18:31:57.4469182","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}\TypeLib","SUCCESS","Desired Access: Read/Write" "18:31:57.4473132","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {5BDB390C-CF8B-4985-A227-F84FB6EBDD3D}" "18:31:57.4597648","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{5BDB390C-CF8B-4985-A227-F84FB6EBDD3D}","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.4603230","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{5BDB390C-CF8B-4985-A227-F84FB6EBDD3D}\1.0","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.4608725","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{5BDB390C-CF8B-4985-A227-F84FB6EBDD3D}\1.0\(Default)","SUCCESS","Type: REG_SZ, Length: 58, Data: HPScripting 1.0 Type Library" "18:31:57.4620626","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{5BDB390C-CF8B-4985-A227-F84FB6EBDD3D}\1.0\FLAGS","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.4634636","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{5BDB390C-CF8B-4985-A227-F84FB6EBDD3D}\1.0\FLAGS\(Default)","SUCCESS","Type: REG_SZ, Length: 4, Data: 0" "18:31:57.4639081","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{5BDB390C-CF8B-4985-A227-F84FB6EBDD3D}\1.0\0","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.4644109","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{5BDB390C-CF8B-4985-A227-F84FB6EBDD3D}\1.0\0\win32","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.4648761","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{5BDB390C-CF8B-4985-A227-F84FB6EBDD3D}\1.0\0\win32\(Default)","SUCCESS","Type: REG_SZ, Length: 50, Data: D:\setup\HPScripting.dll" "18:31:57.4653401","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{5BDB390C-CF8B-4985-A227-F84FB6EBDD3D}\1.0\HELPDIR","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.4657717","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{5BDB390C-CF8B-4985-A227-F84FB6EBDD3D}\1.0\HELPDIR\(Default)","SUCCESS","Type: REG_SZ, Length: 20, Data: D:\setup\" "18:31:57.4665615","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{530DD015-887B-497D-A9B4-B57334C06D14}","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.4677882","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{530DD015-887B-497D-A9B4-B57334C06D14}\(Default)","SUCCESS","Type: REG_SZ, Length: 20, Data: IHPScript" "18:31:57.4683480","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{530DD015-887B-497D-A9B4-B57334C06D14}\ProxyStubClsid","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.4688087","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{530DD015-887B-497D-A9B4-B57334C06D14}\ProxyStubClsid\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:57.4700365","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{530DD015-887B-497D-A9B4-B57334C06D14}\ProxyStubClsid32","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.4705050","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{530DD015-887B-497D-A9B4-B57334C06D14}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:57.4716169","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{530DD015-887B-497D-A9B4-B57334C06D14}\TypeLib","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.4721236","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{530DD015-887B-497D-A9B4-B57334C06D14}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {5BDB390C-CF8B-4985-A227-F84FB6EBDD3D}" "18:31:57.4732766","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{530DD015-887B-497D-A9B4-B57334C06D14}\TypeLib\Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:57.5703154","hpzwup01.exe","3936","RegCreateKey","HKCR\AppID\{DC49F5B4-E4EB-4ED4-A15B-26FE03C9B7E7}","SUCCESS","Desired Access: Read/Write" "18:31:57.5706593","hpzwup01.exe","3936","RegSetValue","HKCR\AppID\{DC49F5B4-E4EB-4ED4-A15B-26FE03C9B7E7}\(Default)","SUCCESS","Type: REG_SZ, Length: 26, Data: InternetUtil" "18:31:57.5712857","hpzwup01.exe","3936","RegCreateKey","HKCR\AppID\InternetUtil.DLL","SUCCESS","Desired Access: Read/Write" "18:31:57.5715701","hpzwup01.exe","3936","RegSetValue","HKCR\AppID\InternetUtil.DLL\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {DC49F5B4-E4EB-4ED4-A15B-26FE03C9B7E7}" "18:31:57.5771831","hpzwup01.exe","3936","RegCreateKey","HKCR\HPInternetUtil.InetCollection.1","SUCCESS","Desired Access: Read/Write" "18:31:57.5774893","hpzwup01.exe","3936","RegSetValue","HKCR\HPInternetUtil.InetCollection.1\(Default)","SUCCESS","Type: REG_SZ, Length: 46, Data: HPInetCollection Class" "18:31:57.5788266","hpzwup01.exe","3936","RegCreateKey","HKCR\HPInternetUtil.InetCollection.1\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.5792590","hpzwup01.exe","3936","RegSetValue","HKCR\HPInternetUtil.InetCollection.1\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {36385AE6-F389-41E3-97DF-7412F61418F8}" "18:31:57.5804251","hpzwup01.exe","3936","RegCreateKey","HKCR\HPInternetUtil.InetCollection","SUCCESS","Desired Access: Read/Write" "18:31:57.5807277","hpzwup01.exe","3936","RegSetValue","HKCR\HPInternetUtil.InetCollection\(Default)","SUCCESS","Type: REG_SZ, Length: 46, Data: HPInetCollection Class" "18:31:57.5818842","hpzwup01.exe","3936","RegCreateKey","HKCR\HPInternetUtil.InetCollection\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.5822957","hpzwup01.exe","3936","RegSetValue","HKCR\HPInternetUtil.InetCollection\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {36385AE6-F389-41E3-97DF-7412F61418F8}" "18:31:57.5834087","hpzwup01.exe","3936","RegCreateKey","HKCR\HPInternetUtil.InetCollection\CurVer","SUCCESS","Desired Access: Read/Write" "18:31:57.5837808","hpzwup01.exe","3936","RegSetValue","HKCR\HPInternetUtil.InetCollection\CurVer\(Default)","SUCCESS","Type: REG_SZ, Length: 64, Data: HPInternetUtil.InetCollection.1" "18:31:57.5845097","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{36385AE6-F389-41E3-97DF-7412F61418F8}","SUCCESS","Desired Access: Read/Write" "18:31:57.5848047","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{36385AE6-F389-41E3-97DF-7412F61418F8}\(Default)","SUCCESS","Type: REG_SZ, Length: 46, Data: HPInetCollection Class" "18:31:57.5859400","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{36385AE6-F389-41E3-97DF-7412F61418F8}\ProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.5863323","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{36385AE6-F389-41E3-97DF-7412F61418F8}\ProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 64, Data: HPInternetUtil.InetCollection.1" "18:31:57.5876540","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{36385AE6-F389-41E3-97DF-7412F61418F8}\VersionIndependentProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.5881051","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{36385AE6-F389-41E3-97DF-7412F61418F8}\VersionIndependentProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 60, Data: HPInternetUtil.InetCollection" "18:31:57.5888675","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{36385AE6-F389-41E3-97DF-7412F61418F8}\Programmable","SUCCESS","Desired Access: Read/Write" "18:31:57.5894983","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{36385AE6-F389-41E3-97DF-7412F61418F8}\InprocServer32","SUCCESS","Desired Access: Read/Write" "18:31:57.5897958","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{36385AE6-F389-41E3-97DF-7412F61418F8}\InprocServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 52, Data: D:\setup\InternetUtil.dll" "18:31:57.6255261","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{36385AE6-F389-41E3-97DF-7412F61418F8}\InprocServer32\ThreadingModel","SUCCESS","Type: REG_SZ, Length: 10, Data: Both" "18:31:57.6260281","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{36385AE6-F389-41E3-97DF-7412F61418F8}\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {DC49F5B4-E4EB-4ED4-A15B-26FE03C9B7E7}" "18:31:57.6268017","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{36385AE6-F389-41E3-97DF-7412F61418F8}\TypeLib","SUCCESS","Desired Access: Read/Write" "18:31:57.6272400","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{36385AE6-F389-41E3-97DF-7412F61418F8}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {B4079907-CE55-44E7-961D-BFA47DD2EBDC}" "18:31:57.6346954","hpzwup01.exe","3936","RegCreateKey","HKCR\HPInternetUtil.InetFile.1","SUCCESS","Desired Access: Read/Write" "18:31:57.6350399","hpzwup01.exe","3936","RegSetValue","HKCR\HPInternetUtil.InetFile.1\(Default)","SUCCESS","Type: REG_SZ, Length: 34, Data: HPInetFile Class" "18:31:57.6356260","hpzwup01.exe","3936","RegCreateKey","HKCR\HPInternetUtil.InetFile.1\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.6360383","hpzwup01.exe","3936","RegSetValue","HKCR\HPInternetUtil.InetFile.1\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {7DB9052D-4CDD-45F7-9EDF-8FE44F19678B}" "18:31:57.6373524","hpzwup01.exe","3936","RegCreateKey","HKCR\HPInternetUtil.InetFile","SUCCESS","Desired Access: Read/Write" "18:31:57.6376589","hpzwup01.exe","3936","RegSetValue","HKCR\HPInternetUtil.InetFile\(Default)","SUCCESS","Type: REG_SZ, Length: 34, Data: HPInetFile Class" "18:31:57.6393927","hpzwup01.exe","3936","RegCreateKey","HKCR\HPInternetUtil.InetFile\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.6398377","hpzwup01.exe","3936","RegSetValue","HKCR\HPInternetUtil.InetFile\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {7DB9052D-4CDD-45F7-9EDF-8FE44F19678B}" "18:31:57.6412627","hpzwup01.exe","3936","RegCreateKey","HKCR\HPInternetUtil.InetFile\CurVer","SUCCESS","Desired Access: Read/Write" "18:31:57.6416862","hpzwup01.exe","3936","RegSetValue","HKCR\HPInternetUtil.InetFile\CurVer\(Default)","SUCCESS","Type: REG_SZ, Length: 52, Data: HPInternetUtil.InetFile.1" "18:31:57.6424025","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7DB9052D-4CDD-45F7-9EDF-8FE44F19678B}","SUCCESS","Desired Access: Read/Write" "18:31:57.6426878","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{7DB9052D-4CDD-45F7-9EDF-8FE44F19678B}\(Default)","SUCCESS","Type: REG_SZ, Length: 34, Data: HPInetFile Class" "18:31:57.6439664","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7DB9052D-4CDD-45F7-9EDF-8FE44F19678B}\ProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.6444290","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{7DB9052D-4CDD-45F7-9EDF-8FE44F19678B}\ProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 52, Data: HPInternetUtil.InetFile.1" "18:31:57.6466863","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7DB9052D-4CDD-45F7-9EDF-8FE44F19678B}\VersionIndependentProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.6471593","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{7DB9052D-4CDD-45F7-9EDF-8FE44F19678B}\VersionIndependentProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 48, Data: HPInternetUtil.InetFile" "18:31:57.6485008","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7DB9052D-4CDD-45F7-9EDF-8FE44F19678B}\Programmable","SUCCESS","Desired Access: Read/Write" "18:31:57.6492501","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7DB9052D-4CDD-45F7-9EDF-8FE44F19678B}\InprocServer32","SUCCESS","Desired Access: Read/Write" "18:31:57.6495931","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{7DB9052D-4CDD-45F7-9EDF-8FE44F19678B}\InprocServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 52, Data: D:\setup\InternetUtil.dll" "18:31:57.6500024","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{7DB9052D-4CDD-45F7-9EDF-8FE44F19678B}\InprocServer32\ThreadingModel","SUCCESS","Type: REG_SZ, Length: 10, Data: Both" "18:31:57.6504689","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{7DB9052D-4CDD-45F7-9EDF-8FE44F19678B}\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {DC49F5B4-E4EB-4ED4-A15B-26FE03C9B7E7}" "18:31:57.6511316","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7DB9052D-4CDD-45F7-9EDF-8FE44F19678B}\TypeLib","SUCCESS","Desired Access: Read/Write" "18:31:57.6515260","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{7DB9052D-4CDD-45F7-9EDF-8FE44F19678B}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {B4079907-CE55-44E7-961D-BFA47DD2EBDC}" "18:31:57.6587183","hpzwup01.exe","3936","RegCreateKey","HKCR\HPInternetUtil.InetService.1","SUCCESS","Desired Access: Read/Write" "18:31:57.6591555","hpzwup01.exe","3936","RegSetValue","HKCR\HPInternetUtil.InetService.1\(Default)","SUCCESS","Type: REG_SZ, Length: 40, Data: HPInetService Class" "18:31:57.6597857","hpzwup01.exe","3936","RegCreateKey","HKCR\HPInternetUtil.InetService.1\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.6601774","hpzwup01.exe","3936","RegSetValue","HKCR\HPInternetUtil.InetService.1\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {6D84BC07-7979-4E59-9589-17E1E5A8FF55}" "18:31:57.6615985","hpzwup01.exe","3936","RegCreateKey","HKCR\HPInternetUtil.InetService","SUCCESS","Desired Access: Read/Write" "18:31:57.6619081","hpzwup01.exe","3936","RegSetValue","HKCR\HPInternetUtil.InetService\(Default)","SUCCESS","Type: REG_SZ, Length: 40, Data: HPInetService Class" "18:31:57.6624257","hpzwup01.exe","3936","RegCreateKey","HKCR\HPInternetUtil.InetService\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.6628266","hpzwup01.exe","3936","RegSetValue","HKCR\HPInternetUtil.InetService\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {6D84BC07-7979-4E59-9589-17E1E5A8FF55}" "18:31:57.6640536","hpzwup01.exe","3936","RegCreateKey","HKCR\HPInternetUtil.InetService\CurVer","SUCCESS","Desired Access: Read/Write" "18:31:57.6644735","hpzwup01.exe","3936","RegSetValue","HKCR\HPInternetUtil.InetService\CurVer\(Default)","SUCCESS","Type: REG_SZ, Length: 58, Data: HPInternetUtil.InetService.1" "18:31:57.6658198","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}","SUCCESS","Desired Access: Read/Write" "18:31:57.6661625","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\(Default)","SUCCESS","Type: REG_SZ, Length: 40, Data: HPInetService Class" "18:31:57.6673144","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\ProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.6677502","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\ProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 58, Data: HPInternetUtil.InetService.1" "18:31:57.6690224","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\VersionIndependentProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.6706883","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\VersionIndependentProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 54, Data: HPInternetUtil.InetService" "18:31:57.6721518","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\Programmable","SUCCESS","Desired Access: Read/Write" "18:31:57.6728184","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\InprocServer32","SUCCESS","Desired Access: Read/Write" "18:31:57.6739155","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\InprocServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 52, Data: D:\setup\InternetUtil.dll" "18:31:57.6782576","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\InprocServer32\ThreadingModel","SUCCESS","Type: REG_SZ, Length: 20, Data: Apartment" "18:31:57.6787030","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {DC49F5B4-E4EB-4ED4-A15B-26FE03C9B7E7}" "18:31:57.6802548","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\Control","SUCCESS","Desired Access: Read/Write" "18:31:57.6810183","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\ToolboxBitmap32","SUCCESS","Desired Access: Read/Write" "18:31:57.6815391","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\ToolboxBitmap32\(Default)","SUCCESS","Type: REG_SZ, Length: 62, Data: D:\setup\InternetUtil.dll, 103" "18:31:57.6821310","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\MiscStatus","SUCCESS","Desired Access: Read/Write" "18:31:57.6824409","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\MiscStatus\(Default)","SUCCESS","Type: REG_SZ, Length: 4, Data: 0" "18:31:57.6829588","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\MiscStatus\1","SUCCESS","Desired Access: Read/Write" "18:31:57.6833547","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\MiscStatus\1\(Default)","SUCCESS","Type: REG_SZ, Length: 14, Data: 132497" "18:31:57.6855105","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\TypeLib","SUCCESS","Desired Access: Read/Write" "18:31:57.6859542","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {B4079907-CE55-44E7-961D-BFA47DD2EBDC}" "18:31:57.6872973","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\Version","SUCCESS","Desired Access: Read/Write" "18:31:57.6876066","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\Version\(Default)","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:57.6971737","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{B4079907-CE55-44E7-961D-BFA47DD2EBDC}","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.6977244","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{B4079907-CE55-44E7-961D-BFA47DD2EBDC}\1.0","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.6982404","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{B4079907-CE55-44E7-961D-BFA47DD2EBDC}\1.0\(Default)","SUCCESS","Type: REG_SZ, Length: 60, Data: InternetUtil 1.0 Type Library" "18:31:57.6995442","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{B4079907-CE55-44E7-961D-BFA47DD2EBDC}\1.0\FLAGS","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.7000596","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{B4079907-CE55-44E7-961D-BFA47DD2EBDC}\1.0\FLAGS\(Default)","SUCCESS","Type: REG_SZ, Length: 4, Data: 0" "18:31:57.7013544","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{B4079907-CE55-44E7-961D-BFA47DD2EBDC}\1.0\0","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.7018593","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{B4079907-CE55-44E7-961D-BFA47DD2EBDC}\1.0\0\win32","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.7023370","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{B4079907-CE55-44E7-961D-BFA47DD2EBDC}\1.0\0\win32\(Default)","SUCCESS","Type: REG_SZ, Length: 52, Data: D:\setup\InternetUtil.dll" "18:31:57.7034310","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{B4079907-CE55-44E7-961D-BFA47DD2EBDC}\1.0\HELPDIR","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.7039137","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{B4079907-CE55-44E7-961D-BFA47DD2EBDC}\1.0\HELPDIR\(Default)","SUCCESS","Type: REG_SZ, Length: 20, Data: D:\setup\" "18:31:57.7059844","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{805150DC-53E0-40DD-99E1-A9F9CEC2E53C}","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.7188346","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{805150DC-53E0-40DD-99E1-A9F9CEC2E53C}\(Default)","SUCCESS","Type: REG_SZ, Length: 44, Data: _IHPInetServiceEvents" "18:31:57.7204186","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{805150DC-53E0-40DD-99E1-A9F9CEC2E53C}\ProxyStubClsid","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.7210055","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{805150DC-53E0-40DD-99E1-A9F9CEC2E53C}\ProxyStubClsid\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020420-0000-0000-C000-000000000046}" "18:31:57.7221440","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{805150DC-53E0-40DD-99E1-A9F9CEC2E53C}\ProxyStubClsid32","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.7226284","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{805150DC-53E0-40DD-99E1-A9F9CEC2E53C}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020420-0000-0000-C000-000000000046}" "18:31:57.7250597","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{805150DC-53E0-40DD-99E1-A9F9CEC2E53C}\TypeLib","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.7255511","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{805150DC-53E0-40DD-99E1-A9F9CEC2E53C}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {B4079907-CE55-44E7-961D-BFA47DD2EBDC}" "18:31:57.7267440","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{805150DC-53E0-40DD-99E1-A9F9CEC2E53C}\TypeLib\Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:57.7274114","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{9ED1A2E2-8A49-4871-B998-FE012390ED3F}","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.7341027","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{9ED1A2E2-8A49-4871-B998-FE012390ED3F}\(Default)","SUCCESS","Type: REG_SZ, Length: 30, Data: IHPInetService" "18:31:57.7346173","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{9ED1A2E2-8A49-4871-B998-FE012390ED3F}\ProxyStubClsid","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.7350976","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{9ED1A2E2-8A49-4871-B998-FE012390ED3F}\ProxyStubClsid\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:57.7373819","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{9ED1A2E2-8A49-4871-B998-FE012390ED3F}\ProxyStubClsid32","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.7378708","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{9ED1A2E2-8A49-4871-B998-FE012390ED3F}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:57.7383857","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{9ED1A2E2-8A49-4871-B998-FE012390ED3F}\TypeLib","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.7388173","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{9ED1A2E2-8A49-4871-B998-FE012390ED3F}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {B4079907-CE55-44E7-961D-BFA47DD2EBDC}" "18:31:57.7423217","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{9ED1A2E2-8A49-4871-B998-FE012390ED3F}\TypeLib\Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:57.7429365","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{0154DB4A-05FA-41AC-A117-FAEB893D483D}","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.7442431","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{0154DB4A-05FA-41AC-A117-FAEB893D483D}\(Default)","SUCCESS","Type: REG_SZ, Length: 36, Data: IHPInetCollection" "18:31:57.7446256","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{0154DB4A-05FA-41AC-A117-FAEB893D483D}\ProxyStubClsid","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.7449779","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{0154DB4A-05FA-41AC-A117-FAEB893D483D}\ProxyStubClsid\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:57.7453408","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{0154DB4A-05FA-41AC-A117-FAEB893D483D}\ProxyStubClsid32","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.7458076","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{0154DB4A-05FA-41AC-A117-FAEB893D483D}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:57.7462062","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{0154DB4A-05FA-41AC-A117-FAEB893D483D}\TypeLib","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.7466714","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{0154DB4A-05FA-41AC-A117-FAEB893D483D}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {B4079907-CE55-44E7-961D-BFA47DD2EBDC}" "18:31:57.7470027","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{0154DB4A-05FA-41AC-A117-FAEB893D483D}\TypeLib\Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:57.7477427","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{B8DCC1F7-D1E4-4224-9D9F-141C557BDF78}","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.7481115","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{B8DCC1F7-D1E4-4224-9D9F-141C557BDF78}\(Default)","SUCCESS","Type: REG_SZ, Length: 24, Data: IHPInetFile" "18:31:57.7484780","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{B8DCC1F7-D1E4-4224-9D9F-141C557BDF78}\ProxyStubClsid","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.7488149","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{B8DCC1F7-D1E4-4224-9D9F-141C557BDF78}\ProxyStubClsid\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:57.7492700","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{B8DCC1F7-D1E4-4224-9D9F-141C557BDF78}\ProxyStubClsid32","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.7497427","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{B8DCC1F7-D1E4-4224-9D9F-141C557BDF78}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:57.7501377","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{B8DCC1F7-D1E4-4224-9D9F-141C557BDF78}\TypeLib","SUCCESS","Desired Access: Maximum Allowed" "18:31:57.7505699","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{B8DCC1F7-D1E4-4224-9D9F-141C557BDF78}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {B4079907-CE55-44E7-961D-BFA47DD2EBDC}" "18:31:57.7508940","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{B8DCC1F7-D1E4-4224-9D9F-141C557BDF78}\TypeLib\Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:57.8124621","hpzwup01.exe","3936","RegCreateKey","HKCR\AppID\{3127F179-FE9E-4E8B-B009-4330342B89B7}","SUCCESS","Desired Access: Read/Write" "18:31:57.8128052","hpzwup01.exe","3936","RegSetValue","HKCR\AppID\{3127F179-FE9E-4E8B-B009-4330342B89B7}\(Default)","SUCCESS","Type: REG_SZ, Length: 24, Data: RulesEngine" "18:31:57.8134287","hpzwup01.exe","3936","RegCreateKey","HKCR\AppID\RulesEngine.DLL","SUCCESS","Desired Access: Read/Write" "18:31:57.8137659","hpzwup01.exe","3936","RegSetValue","HKCR\AppID\RulesEngine.DLL\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {3127F179-FE9E-4E8B-B009-4330342B89B7}" "18:31:57.8196957","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ScriptUtil.1","SUCCESS","Desired Access: Read/Write" "18:31:57.8200438","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ScriptUtil.1\(Default)","SUCCESS","Type: REG_SZ, Length: 34, Data: ScriptUtil Class" "18:31:57.8206121","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ScriptUtil.1\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.8208685","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ScriptUtil.1\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {DF1F1C17-6A29-45fb-A3C6-9825908E062E}" "18:31:57.8213188","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ScriptUtil","SUCCESS","Desired Access: Read/Write" "18:31:57.8216099","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ScriptUtil\(Default)","SUCCESS","Type: REG_SZ, Length: 34, Data: ScriptUtil Class" "18:31:57.8220103","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ScriptUtil\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.8222891","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ScriptUtil\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {DF1F1C17-6A29-45fb-A3C6-9825908E062E}" "18:31:57.8227436","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ScriptUtil\CurVer","SUCCESS","Desired Access: Read/Write" "18:31:57.8231339","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ScriptUtil\CurVer\(Default)","SUCCESS","Type: REG_SZ, Length: 54, Data: HPRulesEngine.ScriptUtil.1" "18:31:57.8237166","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}","SUCCESS","Desired Access: Read/Write" "18:31:57.8240519","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}\(Default)","SUCCESS","Type: REG_SZ, Length: 34, Data: ScriptUtil Class" "18:31:57.8244846","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}\ProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.8247478","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}\ProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 54, Data: HPRulesEngine.ScriptUtil.1" "18:31:57.8252216","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}\VersionIndependentProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.8289723","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}\VersionIndependentProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 50, Data: HPRulesEngine.ScriptUtil" "18:31:57.8296188","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}\Programmable","SUCCESS","Desired Access: Read/Write" "18:31:57.8302678","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}\InprocServer32","SUCCESS","Desired Access: Read/Write" "18:31:57.8306111","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}\InprocServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 50, Data: D:\setup\RulesEngine.dll" "18:31:57.8308645","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}\InprocServer32\ThreadingModel","SUCCESS","Type: REG_SZ, Length: 10, Data: Both" "18:31:57.8313341","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {3127F179-FE9E-4E8B-B009-4330342B89B7}" "18:31:57.8319942","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}\TypeLib","SUCCESS","Desired Access: Read/Write" "18:31:57.8324138","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {C9C10E42-469E-436E-9216-9C6792BC8A70}" "18:31:57.8329438","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{DF1F1C17-6A29-45FB-A3C6-9825908E062E}","SUCCESS","Desired Access: Write" "18:31:57.8331142","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{DF1F1C17-6A29-45FB-A3C6-9825908E062E}\Implemented Categories","SUCCESS","Desired Access: Write" "18:31:57.8334344","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{DF1F1C17-6A29-45FB-A3C6-9825908E062E}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","Desired Access: Write" "18:31:57.8338702","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{DF1F1C17-6A29-45FB-A3C6-9825908E062E}","SUCCESS","Desired Access: Write" "18:31:57.8340325","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{DF1F1C17-6A29-45FB-A3C6-9825908E062E}\Implemented Categories","SUCCESS","Desired Access: Write" "18:31:57.8342169","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{DF1F1C17-6A29-45FB-A3C6-9825908E062E}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","Desired Access: Write" "18:31:57.8652512","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.Content.1","SUCCESS","Desired Access: Read/Write" "18:31:57.8656130","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.Content.1\(Default)","SUCCESS","Type: REG_SZ, Length: 28, Data: Content Class" "18:31:57.8662058","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.Content.1\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.8665894","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.Content.1\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {5A494E87-262C-4340-A539-2FAC0A85D935}" "18:31:57.8689403","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.Content","SUCCESS","Desired Access: Read/Write" "18:31:57.8692872","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.Content\(Default)","SUCCESS","Type: REG_SZ, Length: 28, Data: Content Class" "18:31:57.8721516","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.Content\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.8728924","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.Content\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {5A494E87-262C-4340-A539-2FAC0A85D935}" "18:31:57.8741920","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.Content\CurVer","SUCCESS","Desired Access: Read/Write" "18:31:57.8746167","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.Content\CurVer\(Default)","SUCCESS","Type: REG_SZ, Length: 48, Data: HPRulesEngine.Content.1" "18:31:57.8764261","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{5A494E87-262C-4340-A539-2FAC0A85D935}","SUCCESS","Desired Access: Read/Write" "18:31:57.8767482","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{5A494E87-262C-4340-A539-2FAC0A85D935}\(Default)","SUCCESS","Type: REG_SZ, Length: 28, Data: Content Class" "18:31:57.8781850","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{5A494E87-262C-4340-A539-2FAC0A85D935}\ProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.8785879","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{5A494E87-262C-4340-A539-2FAC0A85D935}\ProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 48, Data: HPRulesEngine.Content.1" "18:31:57.8799906","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{5A494E87-262C-4340-A539-2FAC0A85D935}\VersionIndependentProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.8804928","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{5A494E87-262C-4340-A539-2FAC0A85D935}\VersionIndependentProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 44, Data: HPRulesEngine.Content" "18:31:57.8826001","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{5A494E87-262C-4340-A539-2FAC0A85D935}\Programmable","SUCCESS","Desired Access: Read/Write" "18:31:57.8833016","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{5A494E87-262C-4340-A539-2FAC0A85D935}\InprocServer32","SUCCESS","Desired Access: Read/Write" "18:31:57.8836407","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{5A494E87-262C-4340-A539-2FAC0A85D935}\InprocServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 50, Data: D:\setup\RulesEngine.dll" "18:31:57.8850339","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{5A494E87-262C-4340-A539-2FAC0A85D935}\InprocServer32\ThreadingModel","SUCCESS","Type: REG_SZ, Length: 10, Data: Both" "18:31:57.8855337","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{5A494E87-262C-4340-A539-2FAC0A85D935}\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {3127F179-FE9E-4E8B-B009-4330342B89B7}" "18:31:57.8861810","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{5A494E87-262C-4340-A539-2FAC0A85D935}\TypeLib","SUCCESS","Desired Access: Read/Write" "18:31:57.8865939","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{5A494E87-262C-4340-A539-2FAC0A85D935}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {C9C10E42-469E-436E-9216-9C6792BC8A70}" "18:31:57.8925304","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentProduct.1","SUCCESS","Desired Access: Read/Write" "18:31:57.8928718","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentProduct.1\(Default)","SUCCESS","Type: REG_SZ, Length: 48, Data: HP ContentProduct Class" "18:31:57.8934487","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentProduct.1\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.8938250","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentProduct.1\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}" "18:31:57.8953917","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentProduct","SUCCESS","Desired Access: Read/Write" "18:31:57.8957470","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentProduct\(Default)","SUCCESS","Type: REG_SZ, Length: 48, Data: HP ContentProduct Class" "18:31:57.8969480","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentProduct\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.8973721","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentProduct\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}" "18:31:57.8989318","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentProduct\CurVer","SUCCESS","Desired Access: Read/Write" "18:31:57.8993950","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentProduct\CurVer\(Default)","SUCCESS","Type: REG_SZ, Length: 62, Data: HPRulesEngine.ContentProduct.1" "18:31:57.9018087","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}","SUCCESS","Desired Access: Read/Write" "18:31:57.9021302","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}\(Default)","SUCCESS","Type: REG_SZ, Length: 48, Data: HP ContentProduct Class" "18:31:57.9033650","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}\ProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.9039064","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}\ProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 62, Data: HPRulesEngine.ContentProduct.1" "18:31:57.9053237","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}\VersionIndependentProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.9057259","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}\VersionIndependentProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 58, Data: HPRulesEngine.ContentProduct" "18:31:57.9073479","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}\Programmable","SUCCESS","Desired Access: Read/Write" "18:31:57.9080595","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}\InprocServer32","SUCCESS","Desired Access: Read/Write" "18:31:57.9083721","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}\InprocServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 50, Data: D:\setup\RulesEngine.dll" "18:31:57.9095133","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}\InprocServer32\ThreadingModel","SUCCESS","Type: REG_SZ, Length: 10, Data: Both" "18:31:57.9100533","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {3127F179-FE9E-4E8B-B009-4330342B89B7}" "18:31:57.9107042","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}\TypeLib","SUCCESS","Desired Access: Read/Write" "18:31:57.9111171","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {C9C10E42-469E-436E-9216-9C6792BC8A70}" "18:31:57.9169059","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentOS.1","SUCCESS","Desired Access: Read/Write" "18:31:57.9172752","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentOS.1\(Default)","SUCCESS","Type: REG_SZ, Length: 38, Data: HP ContentOS Class" "18:31:57.9178157","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentOS.1\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.9182259","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentOS.1\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {294E9835-D0F1-4815-8C52-3C08FBB1403E}" "18:31:57.9209298","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentOS","SUCCESS","Desired Access: Read/Write" "18:31:57.9213050","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentOS\(Default)","SUCCESS","Type: REG_SZ, Length: 38, Data: HP ContentOS Class" "18:31:57.9227739","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentOS\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:57.9232170","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentOS\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {294E9835-D0F1-4815-8C52-3C08FBB1403E}" "18:31:57.9390631","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentOS\CurVer","SUCCESS","Desired Access: Read/Write" "18:31:57.9395509","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentOS\CurVer\(Default)","SUCCESS","Type: REG_SZ, Length: 52, Data: HPRulesEngine.ContentOS.1" "18:31:57.9403736","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{294E9835-D0F1-4815-8C52-3C08FBB1403E}","SUCCESS","Desired Access: Read/Write" "18:31:57.9406969","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{294E9835-D0F1-4815-8C52-3C08FBB1403E}\(Default)","SUCCESS","Type: REG_SZ, Length: 38, Data: HP ContentOS Class" "18:31:57.9421845","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{294E9835-D0F1-4815-8C52-3C08FBB1403E}\ProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.9425764","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{294E9835-D0F1-4815-8C52-3C08FBB1403E}\ProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 52, Data: HPRulesEngine.ContentOS.1" "18:31:57.9431782","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{294E9835-D0F1-4815-8C52-3C08FBB1403E}\VersionIndependentProgID","SUCCESS","Desired Access: Read/Write" "18:31:57.9435637","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{294E9835-D0F1-4815-8C52-3C08FBB1403E}\VersionIndependentProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 48, Data: HPRulesEngine.ContentOS" "18:31:57.9556619","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{294E9835-D0F1-4815-8C52-3C08FBB1403E}\Programmable","SUCCESS","Desired Access: Read/Write" "18:31:57.9563659","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{294E9835-D0F1-4815-8C52-3C08FBB1403E}\InprocServer32","SUCCESS","Desired Access: Read/Write" "18:31:57.9566785","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{294E9835-D0F1-4815-8C52-3C08FBB1403E}\InprocServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 50, Data: D:\setup\RulesEngine.dll" "18:31:57.9577800","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{294E9835-D0F1-4815-8C52-3C08FBB1403E}\InprocServer32\ThreadingModel","SUCCESS","Type: REG_SZ, Length: 10, Data: Both" "18:31:57.9672581","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{294E9835-D0F1-4815-8C52-3C08FBB1403E}\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {3127F179-FE9E-4E8B-B009-4330342B89B7}" "18:31:57.9679484","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{294E9835-D0F1-4815-8C52-3C08FBB1403E}\TypeLib","SUCCESS","Desired Access: Read/Write" "18:31:57.9683713","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{294E9835-D0F1-4815-8C52-3C08FBB1403E}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {C9C10E42-469E-436E-9216-9C6792BC8A70}" "18:31:58.0013683","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentFile.1","SUCCESS","Desired Access: Read/Write" "18:31:58.0017415","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentFile.1\(Default)","SUCCESS","Type: REG_SZ, Length: 42, Data: HP ContentFile Class" "18:31:58.0100959","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentFile.1\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:58.0105437","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentFile.1\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {684E4896-6EFC-4A3D-B967-6105894A6796}" "18:31:58.0150532","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentFile","SUCCESS","Desired Access: Read/Write" "18:31:58.0161363","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentFile\(Default)","SUCCESS","Type: REG_SZ, Length: 42, Data: HP ContentFile Class" "18:31:58.0175033","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentFile\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:58.0466263","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentFile\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {684E4896-6EFC-4A3D-B967-6105894A6796}" "18:31:58.0472923","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentFile\CurVer","SUCCESS","Desired Access: Read/Write" "18:31:58.0477719","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentFile\CurVer\(Default)","SUCCESS","Type: REG_SZ, Length: 56, Data: HPRulesEngine.ContentFile.1" "18:31:58.0668825","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{684E4896-6EFC-4A3D-B967-6105894A6796}","SUCCESS","Desired Access: Read/Write" "18:31:58.0672426","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{684E4896-6EFC-4A3D-B967-6105894A6796}\(Default)","SUCCESS","Type: REG_SZ, Length: 42, Data: HP ContentFile Class" "18:31:58.0686274","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{684E4896-6EFC-4A3D-B967-6105894A6796}\ProgID","SUCCESS","Desired Access: Read/Write" "18:31:58.0690311","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{684E4896-6EFC-4A3D-B967-6105894A6796}\ProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 56, Data: HPRulesEngine.ContentFile.1" "18:31:58.0704075","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{684E4896-6EFC-4A3D-B967-6105894A6796}\VersionIndependentProgID","SUCCESS","Desired Access: Read/Write" "18:31:58.0708128","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{684E4896-6EFC-4A3D-B967-6105894A6796}\VersionIndependentProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 52, Data: HPRulesEngine.ContentFile" "18:31:58.0722692","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{684E4896-6EFC-4A3D-B967-6105894A6796}\Programmable","SUCCESS","Desired Access: Read/Write" "18:31:58.0729533","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{684E4896-6EFC-4A3D-B967-6105894A6796}\InprocServer32","SUCCESS","Desired Access: Read/Write" "18:31:58.0732604","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{684E4896-6EFC-4A3D-B967-6105894A6796}\InprocServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 50, Data: D:\setup\RulesEngine.dll" "18:31:58.0736403","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{684E4896-6EFC-4A3D-B967-6105894A6796}\InprocServer32\ThreadingModel","SUCCESS","Type: REG_SZ, Length: 10, Data: Both" "18:31:58.0741295","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{684E4896-6EFC-4A3D-B967-6105894A6796}\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {3127F179-FE9E-4E8B-B009-4330342B89B7}" "18:31:58.0748215","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{684E4896-6EFC-4A3D-B967-6105894A6796}\TypeLib","SUCCESS","Desired Access: Read/Write" "18:31:58.0751835","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{684E4896-6EFC-4A3D-B967-6105894A6796}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {C9C10E42-469E-436E-9216-9C6792BC8A70}" "18:31:58.0832907","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentCollection.1","SUCCESS","Desired Access: Read/Write" "18:31:58.0836757","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentCollection.1\(Default)","SUCCESS","Type: REG_SZ, Length: 48, Data: ContentCollection Class" "18:31:58.0842676","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentCollection.1\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:58.0846451","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentCollection.1\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {7CB9D4F5-C492-42A4-93B1-3F7D6946470D}" "18:31:58.0861994","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentCollection","SUCCESS","Desired Access: Read/Write" "18:31:58.0865101","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentCollection\(Default)","SUCCESS","Type: REG_SZ, Length: 48, Data: ContentCollection Class" "18:31:58.1131699","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentCollection\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:58.1136568","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentCollection\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {7CB9D4F5-C492-42A4-93B1-3F7D6946470D}" "18:31:58.1154789","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentCollection\CurVer","SUCCESS","Desired Access: Read/Write" "18:31:58.1159887","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentCollection\CurVer\(Default)","SUCCESS","Type: REG_SZ, Length: 68, Data: HPRulesEngine.ContentCollection.1" "18:31:58.1174805","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}","SUCCESS","Desired Access: Read/Write" "18:31:58.1178213","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\(Default)","SUCCESS","Type: REG_SZ, Length: 48, Data: ContentCollection Class" "18:31:58.1184080","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\ProgID","SUCCESS","Desired Access: Read/Write" "18:31:58.1188343","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\ProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 68, Data: HPRulesEngine.ContentCollection.1" "18:31:58.1201563","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\VersionIndependentProgID","SUCCESS","Desired Access: Read/Write" "18:31:58.1246845","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\VersionIndependentProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 64, Data: HPRulesEngine.ContentCollection" "18:31:58.1453399","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\Programmable","SUCCESS","Desired Access: Read/Write" "18:31:58.1460408","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\InprocServer32","SUCCESS","Desired Access: Read/Write" "18:31:58.1463574","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\InprocServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 50, Data: D:\setup\RulesEngine.dll" "18:31:58.1480567","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\InprocServer32\ThreadingModel","SUCCESS","Type: REG_SZ, Length: 10, Data: Both" "18:31:58.1485317","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {3127F179-FE9E-4E8B-B009-4330342B89B7}" "18:31:58.1491946","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\TypeLib","SUCCESS","Desired Access: Read/Write" "18:31:58.1545707","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {C9C10E42-469E-436E-9216-9C6792BC8A70}" "18:31:58.1552325","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}","SUCCESS","Desired Access: Write" "18:31:58.1554057","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\Implemented Categories","SUCCESS","Desired Access: Write" "18:31:58.1556996","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","Desired Access: Write" "18:31:58.1560960","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}","SUCCESS","Desired Access: Write" "18:31:58.1562874","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\Implemented Categories","SUCCESS","Desired Access: Write" "18:31:58.1564768","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","Desired Access: Write" "18:31:58.1613179","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentFinder.1","SUCCESS","Desired Access: Read/Write" "18:31:58.1616872","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentFinder.1\(Default)","SUCCESS","Type: REG_SZ, Length: 40, Data: ContentFinder Class" "18:31:58.1620901","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentFinder.1\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:58.1623753","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentFinder.1\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {BE65189A-4770-47A0-9B7B-68827DB1C317}" "18:31:58.1627519","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentFinder","SUCCESS","Desired Access: Read/Write" "18:31:58.1630380","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentFinder\(Default)","SUCCESS","Type: REG_SZ, Length: 40, Data: ContentFinder Class" "18:31:58.1635447","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentFinder\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:58.1637931","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentFinder\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {BE65189A-4770-47A0-9B7B-68827DB1C317}" "18:31:58.1642225","hpzwup01.exe","3936","RegCreateKey","HKCR\HPRulesEngine.ContentFinder\CurVer","SUCCESS","Desired Access: Read/Write" "18:31:58.1645566","hpzwup01.exe","3936","RegSetValue","HKCR\HPRulesEngine.ContentFinder\CurVer\(Default)","SUCCESS","Type: REG_SZ, Length: 60, Data: HPRulesEngine.ContentFinder.1" "18:31:58.1651327","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}","SUCCESS","Desired Access: Read/Write" "18:31:58.1674623","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\(Default)","SUCCESS","Type: REG_SZ, Length: 40, Data: ContentFinder Class" "18:31:58.1679554","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\ProgID","SUCCESS","Desired Access: Read/Write" "18:31:58.1682733","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\ProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 60, Data: HPRulesEngine.ContentFinder.1" "18:31:58.1687398","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\VersionIndependentProgID","SUCCESS","Desired Access: Read/Write" "18:31:58.1694528","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\VersionIndependentProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 56, Data: HPRulesEngine.ContentFinder" "18:31:58.1700241","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\Programmable","SUCCESS","Desired Access: Read/Write" "18:31:58.1706381","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\InprocServer32","SUCCESS","Desired Access: Read/Write" "18:31:58.1709353","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\InprocServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 50, Data: D:\setup\RulesEngine.dll" "18:31:58.1711653","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\InprocServer32\ThreadingModel","SUCCESS","Type: REG_SZ, Length: 20, Data: Apartment" "18:31:58.1748789","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {3127F179-FE9E-4E8B-B009-4330342B89B7}" "18:31:58.1756130","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\Control","SUCCESS","Desired Access: Read/Write" "18:31:58.1763793","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\ToolboxBitmap32","SUCCESS","Desired Access: Read/Write" "18:31:58.1766861","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\ToolboxBitmap32\(Default)","SUCCESS","Type: REG_SZ, Length: 60, Data: D:\setup\RulesEngine.dll, 202" "18:31:58.1771856","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\MiscStatus","SUCCESS","Desired Access: Read/Write" "18:31:58.1775404","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\MiscStatus\(Default)","SUCCESS","Type: REG_SZ, Length: 4, Data: 0" "18:31:58.1780566","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\MiscStatus\1","SUCCESS","Desired Access: Read/Write" "18:31:58.1783290","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\MiscStatus\1\(Default)","SUCCESS","Type: REG_SZ, Length: 14, Data: 132497" "18:31:58.1788020","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\TypeLib","SUCCESS","Desired Access: Read/Write" "18:31:58.1791546","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {C9C10E42-469E-436E-9216-9C6792BC8A70}" "18:31:58.1796108","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\Version","SUCCESS","Desired Access: Read/Write" "18:31:58.1799438","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\Version\(Default)","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:58.1803701","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\Marcon","SUCCESS","Desired Access: Read/Write" "18:31:58.1808402","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\Marcon\(Default)","SUCCESS","Type: REG_SZ, Length: 40, Data: rules_engine_3_test" "18:31:58.1812682","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}","SUCCESS","Desired Access: Write" "18:31:58.1814347","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\Implemented Categories","SUCCESS","Desired Access: Write" "18:31:58.1817560","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","Desired Access: Write" "18:31:58.1820789","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}","SUCCESS","Desired Access: Write" "18:31:58.1822399","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\Implemented Categories","SUCCESS","Desired Access: Write" "18:31:58.1824108","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","Desired Access: Write" "18:31:58.1953943","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{C9C10E42-469E-436E-9216-9C6792BC8A70}","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.1958827","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{C9C10E42-469E-436E-9216-9C6792BC8A70}\1.0","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.1962707","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{C9C10E42-469E-436E-9216-9C6792BC8A70}\1.0\(Default)","SUCCESS","Type: REG_SZ, Length: 58, Data: RulesEngine 1.0 Type Library" "18:31:58.1966445","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{C9C10E42-469E-436E-9216-9C6792BC8A70}\1.0\FLAGS","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.1970219","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{C9C10E42-469E-436E-9216-9C6792BC8A70}\1.0\FLAGS\(Default)","SUCCESS","Type: REG_SZ, Length: 4, Data: 0" "18:31:58.1973870","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{C9C10E42-469E-436E-9216-9C6792BC8A70}\1.0\0","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.1978435","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{C9C10E42-469E-436E-9216-9C6792BC8A70}\1.0\0\win32","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.1982288","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{C9C10E42-469E-436E-9216-9C6792BC8A70}\1.0\0\win32\(Default)","SUCCESS","Type: REG_SZ, Length: 50, Data: D:\setup\RulesEngine.dll" "18:31:58.1985363","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{C9C10E42-469E-436E-9216-9C6792BC8A70}\1.0\HELPDIR","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.1990009","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{C9C10E42-469E-436E-9216-9C6792BC8A70}\1.0\HELPDIR\(Default)","SUCCESS","Type: REG_SZ, Length: 20, Data: D:\setup\" "18:31:58.1994630","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{DF4536A8-BF2D-4834-A454-8FAD9B120005}","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.1998767","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{DF4536A8-BF2D-4834-A454-8FAD9B120005}\(Default)","SUCCESS","Type: REG_SZ, Length: 48, Data: _IHPContentFinderEvents" "18:31:58.2001790","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{DF4536A8-BF2D-4834-A454-8FAD9B120005}\ProxyStubClsid","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2006615","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{DF4536A8-BF2D-4834-A454-8FAD9B120005}\ProxyStubClsid\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020420-0000-0000-C000-000000000046}" "18:31:58.2010389","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{DF4536A8-BF2D-4834-A454-8FAD9B120005}\ProxyStubClsid32","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2014409","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{DF4536A8-BF2D-4834-A454-8FAD9B120005}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020420-0000-0000-C000-000000000046}" "18:31:58.2018393","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{DF4536A8-BF2D-4834-A454-8FAD9B120005}\TypeLib","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2024226","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{DF4536A8-BF2D-4834-A454-8FAD9B120005}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {C9C10E42-469E-436E-9216-9C6792BC8A70}" "18:31:58.2027690","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{DF4536A8-BF2D-4834-A454-8FAD9B120005}\TypeLib\Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:58.2032914","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{4C99B6E9-C553-4E2C-8402-C7D31291B32A}","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2049246","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{4C99B6E9-C553-4E2C-8402-C7D31291B32A}\(Default)","SUCCESS","Type: REG_SZ, Length: 28, Data: IHPScriptUtil" "18:31:58.2053137","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{4C99B6E9-C553-4E2C-8402-C7D31291B32A}\ProxyStubClsid","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2056590","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{4C99B6E9-C553-4E2C-8402-C7D31291B32A}\ProxyStubClsid\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:58.2060010","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{4C99B6E9-C553-4E2C-8402-C7D31291B32A}\ProxyStubClsid32","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2064714","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{4C99B6E9-C553-4E2C-8402-C7D31291B32A}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:58.2068164","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{4C99B6E9-C553-4E2C-8402-C7D31291B32A}\TypeLib","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2072824","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{4C99B6E9-C553-4E2C-8402-C7D31291B32A}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {C9C10E42-469E-436E-9216-9C6792BC8A70}" "18:31:58.2075889","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{4C99B6E9-C553-4E2C-8402-C7D31291B32A}\TypeLib\Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:58.2088969","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{ED9F739F-B63F-4D14-A555-F7F11F3FDCD9}","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2098805","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{ED9F739F-B63F-4D14-A555-F7F11F3FDCD9}\(Default)","SUCCESS","Type: REG_SZ, Length: 22, Data: IHPContent" "18:31:58.2103448","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{ED9F739F-B63F-4D14-A555-F7F11F3FDCD9}\ProxyStubClsid","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2107298","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{ED9F739F-B63F-4D14-A555-F7F11F3FDCD9}\ProxyStubClsid\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:58.2111399","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{ED9F739F-B63F-4D14-A555-F7F11F3FDCD9}\ProxyStubClsid32","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2115444","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{ED9F739F-B63F-4D14-A555-F7F11F3FDCD9}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:58.2119210","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{ED9F739F-B63F-4D14-A555-F7F11F3FDCD9}\TypeLib","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2123454","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{ED9F739F-B63F-4D14-A555-F7F11F3FDCD9}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {C9C10E42-469E-436E-9216-9C6792BC8A70}" "18:31:58.2126873","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{ED9F739F-B63F-4D14-A555-F7F11F3FDCD9}\TypeLib\Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:58.2131533","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{30F72035-66AE-45D9-A2A7-AC3FBADCE793}","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2137838","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{30F72035-66AE-45D9-A2A7-AC3FBADCE793}\(Default)","SUCCESS","Type: REG_SZ, Length: 42, Data: IHPContentCollection" "18:31:58.2141453","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{30F72035-66AE-45D9-A2A7-AC3FBADCE793}\ProxyStubClsid","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2145328","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{30F72035-66AE-45D9-A2A7-AC3FBADCE793}\ProxyStubClsid\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:58.2193326","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{30F72035-66AE-45D9-A2A7-AC3FBADCE793}\ProxyStubClsid32","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2197790","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{30F72035-66AE-45D9-A2A7-AC3FBADCE793}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:58.2202916","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{30F72035-66AE-45D9-A2A7-AC3FBADCE793}\TypeLib","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2207017","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{30F72035-66AE-45D9-A2A7-AC3FBADCE793}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {C9C10E42-469E-436E-9216-9C6792BC8A70}" "18:31:58.2211387","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{30F72035-66AE-45D9-A2A7-AC3FBADCE793}\TypeLib\Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:58.2216611","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{4EE1F6B7-1C7A-46AF-AD5D-4BD3E9FB2CBE}","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2220458","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{4EE1F6B7-1C7A-46AF-AD5D-4BD3E9FB2CBE}\(Default)","SUCCESS","Type: REG_SZ, Length: 34, Data: IHPContentFinder" "18:31:58.2223810","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{4EE1F6B7-1C7A-46AF-AD5D-4BD3E9FB2CBE}\ProxyStubClsid","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2228213","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{4EE1F6B7-1C7A-46AF-AD5D-4BD3E9FB2CBE}\ProxyStubClsid\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:58.2232174","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{4EE1F6B7-1C7A-46AF-AD5D-4BD3E9FB2CBE}\ProxyStubClsid32","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2238795","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{4EE1F6B7-1C7A-46AF-AD5D-4BD3E9FB2CBE}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:58.2242217","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{4EE1F6B7-1C7A-46AF-AD5D-4BD3E9FB2CBE}\TypeLib","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2246659","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{4EE1F6B7-1C7A-46AF-AD5D-4BD3E9FB2CBE}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {C9C10E42-469E-436E-9216-9C6792BC8A70}" "18:31:58.2249727","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{4EE1F6B7-1C7A-46AF-AD5D-4BD3E9FB2CBE}\TypeLib\Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:58.2254780","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{78D329A0-795E-46E2-86E1-5C13C930302D}","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2258560","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{78D329A0-795E-46E2-86E1-5C13C930302D}\(Default)","SUCCESS","Type: REG_SZ, Length: 30, Data: IHPContentFile" "18:31:58.2261619","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{78D329A0-795E-46E2-86E1-5C13C930302D}\ProxyStubClsid","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2265441","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{78D329A0-795E-46E2-86E1-5C13C930302D}\ProxyStubClsid\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:58.2268872","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{78D329A0-795E-46E2-86E1-5C13C930302D}\ProxyStubClsid32","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2273224","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{78D329A0-795E-46E2-86E1-5C13C930302D}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:58.2276965","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{78D329A0-795E-46E2-86E1-5C13C930302D}\TypeLib","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2281594","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{78D329A0-795E-46E2-86E1-5C13C930302D}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {C9C10E42-469E-436E-9216-9C6792BC8A70}" "18:31:58.2284678","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{78D329A0-795E-46E2-86E1-5C13C930302D}\TypeLib\Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:58.2289852","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{FDD27BD5-AA4A-4A4C-9EB1-06F1E1BB2B63}","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2294665","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{FDD27BD5-AA4A-4A4C-9EB1-06F1E1BB2B63}\(Default)","SUCCESS","Type: REG_SZ, Length: 26, Data: IHPContentOS" "18:31:58.2298001","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{FDD27BD5-AA4A-4A4C-9EB1-06F1E1BB2B63}\ProxyStubClsid","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2301890","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{FDD27BD5-AA4A-4A4C-9EB1-06F1E1BB2B63}\ProxyStubClsid\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:58.2305334","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{FDD27BD5-AA4A-4A4C-9EB1-06F1E1BB2B63}\ProxyStubClsid32","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2309740","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{FDD27BD5-AA4A-4A4C-9EB1-06F1E1BB2B63}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:58.2313170","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{FDD27BD5-AA4A-4A4C-9EB1-06F1E1BB2B63}\TypeLib","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2318758","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{FDD27BD5-AA4A-4A4C-9EB1-06F1E1BB2B63}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {C9C10E42-469E-436E-9216-9C6792BC8A70}" "18:31:58.2322557","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{FDD27BD5-AA4A-4A4C-9EB1-06F1E1BB2B63}\TypeLib\Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:58.2327463","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{1F092142-2520-46F9-A293-EF85C72DCF74}","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2355257","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{1F092142-2520-46F9-A293-EF85C72DCF74}\(Default)","SUCCESS","Type: REG_SZ, Length: 36, Data: IHPContentProduct" "18:31:58.2358743","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{1F092142-2520-46F9-A293-EF85C72DCF74}\ProxyStubClsid","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2364398","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{1F092142-2520-46F9-A293-EF85C72DCF74}\ProxyStubClsid\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:58.2367817","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{1F092142-2520-46F9-A293-EF85C72DCF74}\ProxyStubClsid32","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2372122","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{1F092142-2520-46F9-A293-EF85C72DCF74}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:58.2375589","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{1F092142-2520-46F9-A293-EF85C72DCF74}\TypeLib","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.2400749","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{1F092142-2520-46F9-A293-EF85C72DCF74}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {C9C10E42-469E-436E-9216-9C6792BC8A70}" "18:31:58.2404305","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{1F092142-2520-46F9-A293-EF85C72DCF74}\TypeLib\Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:58.3071066","hpzwup01.exe","3936","RegCreateKey","HKCR\AppID\{2F16B25F-1B36-4B7B-A972-4C56E7F04AC5}","SUCCESS","Desired Access: Read/Write" "18:31:58.3074616","hpzwup01.exe","3936","RegSetValue","HKCR\AppID\{2F16B25F-1B36-4B7B-A972-4C56E7F04AC5}\(Default)","SUCCESS","Type: REG_SZ, Length: 30, Data: InstallMetrics" "18:31:58.3079396","hpzwup01.exe","3936","RegCreateKey","HKCR\AppID\InstallMetrics.DLL","SUCCESS","Desired Access: Read/Write" "18:31:58.3082263","hpzwup01.exe","3936","RegSetValue","HKCR\AppID\InstallMetrics.DLL\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {2F16B25F-1B36-4B7B-A972-4C56E7F04AC5}" "18:31:58.3128347","hpzwup01.exe","3936","RegCreateKey","HKCR\InstallMetrics.CInstallMetrics.1","SUCCESS","Desired Access: Read/Write" "18:31:58.3131691","hpzwup01.exe","3936","RegSetValue","HKCR\InstallMetrics.CInstallMetrics.1\(Default)","SUCCESS","Type: REG_SZ, Length: 44, Data: CInstallMetrics Class" "18:31:58.3136040","hpzwup01.exe","3936","RegCreateKey","HKCR\InstallMetrics.CInstallMetrics.1\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:58.3138566","hpzwup01.exe","3936","RegSetValue","HKCR\InstallMetrics.CInstallMetrics.1\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {D446CB6C-DEC5-4169-92D2-AF110CB78FF7}" "18:31:58.3143220","hpzwup01.exe","3936","RegCreateKey","HKCR\InstallMetrics.CInstallMetrics","SUCCESS","Desired Access: Read/Write" "18:31:58.3146424","hpzwup01.exe","3936","RegSetValue","HKCR\InstallMetrics.CInstallMetrics\(Default)","SUCCESS","Type: REG_SZ, Length: 44, Data: CInstallMetrics Class" "18:31:58.3150305","hpzwup01.exe","3936","RegCreateKey","HKCR\InstallMetrics.CInstallMetrics\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:58.3152763","hpzwup01.exe","3936","RegSetValue","HKCR\InstallMetrics.CInstallMetrics\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {D446CB6C-DEC5-4169-92D2-AF110CB78FF7}" "18:31:58.3156926","hpzwup01.exe","3936","RegCreateKey","HKCR\InstallMetrics.CInstallMetrics\CurVer","SUCCESS","Desired Access: Read/Write" "18:31:58.3160317","hpzwup01.exe","3936","RegSetValue","HKCR\InstallMetrics.CInstallMetrics\CurVer\(Default)","SUCCESS","Type: REG_SZ, Length: 66, Data: InstallMetrics.CInstallMetrics.1" "18:31:58.3165863","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{D446CB6C-DEC5-4169-92D2-AF110CB78FF7}","SUCCESS","Desired Access: Read/Write" "18:31:58.3169332","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{D446CB6C-DEC5-4169-92D2-AF110CB78FF7}\(Default)","SUCCESS","Type: REG_SZ, Length: 44, Data: CInstallMetrics Class" "18:31:58.3173447","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{D446CB6C-DEC5-4169-92D2-AF110CB78FF7}\ProgID","SUCCESS","Desired Access: Read/Write" "18:31:58.3176034","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{D446CB6C-DEC5-4169-92D2-AF110CB78FF7}\ProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 66, Data: InstallMetrics.CInstallMetrics.1" "18:31:58.3181239","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{D446CB6C-DEC5-4169-92D2-AF110CB78FF7}\VersionIndependentProgID","SUCCESS","Desired Access: Read/Write" "18:31:58.3184804","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{D446CB6C-DEC5-4169-92D2-AF110CB78FF7}\VersionIndependentProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 62, Data: InstallMetrics.CInstallMetrics" "18:31:58.3189908","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{D446CB6C-DEC5-4169-92D2-AF110CB78FF7}\Programmable","SUCCESS","Desired Access: Read/Write" "18:31:58.3196210","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{D446CB6C-DEC5-4169-92D2-AF110CB78FF7}\InprocServer32","SUCCESS","Desired Access: Read/Write" "18:31:58.3199205","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{D446CB6C-DEC5-4169-92D2-AF110CB78FF7}\InprocServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 56, Data: D:\setup\InstallMetrics.dll" "18:31:58.3201487","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{D446CB6C-DEC5-4169-92D2-AF110CB78FF7}\InprocServer32\ThreadingModel","SUCCESS","Type: REG_SZ, Length: 20, Data: Apartment" "18:31:58.3204574","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{D446CB6C-DEC5-4169-92D2-AF110CB78FF7}\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {2F16B25F-1B36-4B7B-A972-4C56E7F04AC5}" "18:31:58.3209536","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{D446CB6C-DEC5-4169-92D2-AF110CB78FF7}\TypeLib","SUCCESS","Desired Access: Read/Write" "18:31:58.3213070","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{D446CB6C-DEC5-4169-92D2-AF110CB78FF7}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {55676750-8EC2-4C6C-8717-F5984FC25275}" "18:31:58.3321050","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{55676750-8EC2-4C6C-8717-F5984FC25275}","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.3325749","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{55676750-8EC2-4C6C-8717-F5984FC25275}\1.0","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.3329755","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{55676750-8EC2-4C6C-8717-F5984FC25275}\1.0\(Default)","SUCCESS","Type: REG_SZ, Length: 64, Data: InstallMetrics 1.0 Type Library" "18:31:58.3332990","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{55676750-8EC2-4C6C-8717-F5984FC25275}\1.0\FLAGS","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.3336999","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{55676750-8EC2-4C6C-8717-F5984FC25275}\1.0\FLAGS\(Default)","SUCCESS","Type: REG_SZ, Length: 4, Data: 0" "18:31:58.3340731","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{55676750-8EC2-4C6C-8717-F5984FC25275}\1.0\0","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.3345358","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{55676750-8EC2-4C6C-8717-F5984FC25275}\1.0\0\win32","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.3348894","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{55676750-8EC2-4C6C-8717-F5984FC25275}\1.0\0\win32\(Default)","SUCCESS","Type: REG_SZ, Length: 56, Data: D:\setup\InstallMetrics.dll" "18:31:58.3352322","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{55676750-8EC2-4C6C-8717-F5984FC25275}\1.0\HELPDIR","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.3356384","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{55676750-8EC2-4C6C-8717-F5984FC25275}\1.0\HELPDIR\(Default)","SUCCESS","Type: REG_SZ, Length: 20, Data: D:\setup\" "18:31:58.3360952","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.3365265","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\(Default)","SUCCESS","Type: REG_SZ, Length: 34, Data: ICInstallMetrics" "18:31:58.3394679","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\ProxyStubClsid","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.3398875","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\ProxyStubClsid\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:58.3402415","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\ProxyStubClsid32","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.3406525","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:58.3695022","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\TypeLib","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.3700120","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {55676750-8EC2-4C6C-8717-F5984FC25275}" "18:31:58.3703716","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\TypeLib\Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:58.3930261","hpzwup01.exe","3936","RegCreateKey","HKCU\Software\Classes\CLSID","SUCCESS","Desired Access: Write" "18:31:58.3932253","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}","SUCCESS","Desired Access: Write" "18:31:58.3939008","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\InProcServer32","SUCCESS","Desired Access: Write" "18:31:58.3944252","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\InProcServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 56, Data: D:\setup\InstallMetrics.dll" "18:31:58.3946451","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\InProcServer32\ThreadingModel","SUCCESS","Type: REG_SZ, Length: 10, Data: Both" "18:31:58.3949328","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\(Default)","SUCCESS","Type: REG_SZ, Length: 32, Data: PSFactoryBuffer" "18:31:58.3951893","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface","SUCCESS","Desired Access: Write" "18:31:58.3953516","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}","SUCCESS","Desired Access: Write" "18:31:58.3955061","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\ProxyStubClsid32","SUCCESS","Desired Access: Write" "18:31:58.3956815","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {12E91406-2C17-43ED-8D2F-E1CAE7701DA9}" "18:31:58.3958324","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\(Default)","SUCCESS","Type: REG_SZ, Length: 34, Data: ICInstallMetrics" "18:31:58.3959514","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\NumMethods","SUCCESS","Desired Access: Write" "18:31:58.3962492","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\NumMethods\(Default)","SUCCESS","Type: REG_SZ, Length: 6, Data: 19" "18:31:58.4586289","hpzwup01.exe","3936","RegCreateKey","HKCR\AppID\{12B34448-B1B9-48D7-A98B-142AAD6C651F}","SUCCESS","Desired Access: Read/Write" "18:31:58.4591292","hpzwup01.exe","3936","RegSetValue","HKCR\AppID\{12B34448-B1B9-48D7-A98B-142AAD6C651F}\(Default)","SUCCESS","Type: REG_SZ, Length: 22, Data: HPeSupport" "18:31:58.4596162","hpzwup01.exe","3936","RegCreateKey","HKCR\AppID\HPeSupport.DLL","SUCCESS","Desired Access: Read/Write" "18:31:58.4599120","hpzwup01.exe","3936","RegSetValue","HKCR\AppID\HPeSupport.DLL\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {12B34448-B1B9-48D7-A98B-142AAD6C651F}" "18:31:58.4717686","hpzwup01.exe","3936","RegCreateKey","HKCR\HPeSupport.HPStamper.1","SUCCESS","Desired Access: Read/Write" "18:31:58.4721295","hpzwup01.exe","3936","RegSetValue","HKCR\HPeSupport.HPStamper.1\(Default)","SUCCESS","Type: REG_SZ, Length: 32, Data: HPStamper Class" "18:31:58.4725731","hpzwup01.exe","3936","RegCreateKey","HKCR\HPeSupport.HPStamper.1\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:58.4728612","hpzwup01.exe","3936","RegSetValue","HKCR\HPeSupport.HPStamper.1\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {63B3EC14-9F70-4129-B935-46EFB37013E8}" "18:31:58.4732341","hpzwup01.exe","3936","RegCreateKey","HKCR\HPeSupport.HPStamper","SUCCESS","Desired Access: Read/Write" "18:31:58.4735160","hpzwup01.exe","3936","RegSetValue","HKCR\HPeSupport.HPStamper\(Default)","SUCCESS","Type: REG_SZ, Length: 32, Data: HPStamper Class" "18:31:58.4739222","hpzwup01.exe","3936","RegCreateKey","HKCR\HPeSupport.HPStamper\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:58.4743552","hpzwup01.exe","3936","RegSetValue","HKCR\HPeSupport.HPStamper\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {63B3EC14-9F70-4129-B935-46EFB37013E8}" "18:31:58.4747388","hpzwup01.exe","3936","RegCreateKey","HKCR\HPeSupport.HPStamper\CurVer","SUCCESS","Desired Access: Read/Write" "18:31:58.4751128","hpzwup01.exe","3936","RegSetValue","HKCR\HPeSupport.HPStamper\CurVer\(Default)","SUCCESS","Type: REG_SZ, Length: 46, Data: HPeSupport.HPStamper.1" "18:31:58.4757157","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}","SUCCESS","Desired Access: Read/Write" "18:31:58.4760554","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\(Default)","SUCCESS","Type: REG_SZ, Length: 32, Data: HPStamper Class" "18:31:58.4765069","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\ProgID","SUCCESS","Desired Access: Read/Write" "18:31:58.4767658","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\ProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 46, Data: HPeSupport.HPStamper.1" "18:31:58.4771824","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\VersionIndependentProgID","SUCCESS","Desired Access: Read/Write" "18:31:58.4775777","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\VersionIndependentProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 42, Data: HPeSupport.HPStamper" "18:31:58.4781182","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\Programmable","SUCCESS","Desired Access: Read/Write" "18:31:58.4787166","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\InprocServer32","SUCCESS","Desired Access: Read/Write" "18:31:58.4791511","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\InprocServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 48, Data: D:\setup\HPeSupport.dll" "18:31:58.4794145","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\InprocServer32\ThreadingModel","SUCCESS","Type: REG_SZ, Length: 20, Data: Apartment" "18:31:58.4797204","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {12B34448-B1B9-48D7-A98B-142AAD6C651F}" "18:31:58.4801911","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\TypeLib","SUCCESS","Desired Access: Read/Write" "18:31:58.4805417","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {DE68F9EC-CBEC-416E-9719-6923F0128D76}" "18:31:58.4846099","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}","SUCCESS","Desired Access: Write" "18:31:58.4847864","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\Implemented Categories","SUCCESS","Desired Access: Write" "18:31:58.4850864","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","Desired Access: Write" "18:31:58.4854826","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}","SUCCESS","Desired Access: Write" "18:31:58.4856491","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\Implemented Categories","SUCCESS","Desired Access: Write" "18:31:58.4857927","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","Desired Access: Write" "18:31:58.4925751","hpzwup01.exe","3936","RegCreateKey","HKCR\HPeSupport.HPStamper2.1","SUCCESS","Desired Access: Read/Write" "18:31:58.4929190","hpzwup01.exe","3936","RegSetValue","HKCR\HPeSupport.HPStamper2.1\(Default)","SUCCESS","Type: REG_SZ, Length: 34, Data: HPStamper2 Class" "18:31:58.4933671","hpzwup01.exe","3936","RegCreateKey","HKCR\HPeSupport.HPStamper2.1\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:58.4936495","hpzwup01.exe","3936","RegSetValue","HKCR\HPeSupport.HPStamper2.1\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}" "18:31:58.4940317","hpzwup01.exe","3936","RegCreateKey","HKCR\HPeSupport.HPStamper2","SUCCESS","Desired Access: Read/Write" "18:31:58.4943183","hpzwup01.exe","3936","RegSetValue","HKCR\HPeSupport.HPStamper2\(Default)","SUCCESS","Type: REG_SZ, Length: 34, Data: HPStamper2 Class" "18:31:58.4947963","hpzwup01.exe","3936","RegCreateKey","HKCR\HPeSupport.HPStamper2\CLSID","SUCCESS","Desired Access: Read/Write" "18:31:58.4950461","hpzwup01.exe","3936","RegSetValue","HKCR\HPeSupport.HPStamper2\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}" "18:31:58.4954241","hpzwup01.exe","3936","RegCreateKey","HKCR\HPeSupport.HPStamper2\CurVer","SUCCESS","Desired Access: Read/Write" "18:31:58.4957937","hpzwup01.exe","3936","RegSetValue","HKCR\HPeSupport.HPStamper2\CurVer\(Default)","SUCCESS","Type: REG_SZ, Length: 48, Data: HPeSupport.HPStamper2.1" "18:31:58.4963708","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}","SUCCESS","Desired Access: Read/Write" "18:31:58.4966608","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\(Default)","SUCCESS","Type: REG_SZ, Length: 34, Data: HPStamper2 Class" "18:31:58.4971014","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\ProgID","SUCCESS","Desired Access: Read/Write" "18:31:58.4979074","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\ProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 48, Data: HPeSupport.HPStamper2.1" "18:31:58.4983362","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\VersionIndependentProgID","SUCCESS","Desired Access: Read/Write" "18:31:58.4987468","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\VersionIndependentProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 44, Data: HPeSupport.HPStamper2" "18:31:58.4995654","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\Programmable","SUCCESS","Desired Access: Read/Write" "18:31:58.5001881","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\InprocServer32","SUCCESS","Desired Access: Read/Write" "18:31:58.5005314","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\InprocServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 48, Data: D:\setup\HPeSupport.dll" "18:31:58.5007641","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\InprocServer32\ThreadingModel","SUCCESS","Type: REG_SZ, Length: 20, Data: Apartment" "18:31:58.5010262","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {12B34448-B1B9-48D7-A98B-142AAD6C651F}" "18:31:58.5015218","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\TypeLib","SUCCESS","Desired Access: Read/Write" "18:31:58.5019308","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {DE68F9EC-CBEC-416E-9719-6923F0128D76}" "18:31:58.5023551","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}","SUCCESS","Desired Access: Write" "18:31:58.5025619","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\Implemented Categories","SUCCESS","Desired Access: Write" "18:31:58.5028742","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","Desired Access: Write" "18:31:58.5032022","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}","SUCCESS","Desired Access: Write" "18:31:58.5033642","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\Implemented Categories","SUCCESS","Desired Access: Write" "18:31:58.5035111","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","Desired Access: Write" "18:31:58.5133596","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{DE68F9EC-CBEC-416E-9719-6923F0128D76}","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.5138708","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{DE68F9EC-CBEC-416E-9719-6923F0128D76}\1.0","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.5142502","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{DE68F9EC-CBEC-416E-9719-6923F0128D76}\1.0\(Default)","SUCCESS","Type: REG_SZ, Length: 56, Data: HPeSupport 1.0 Type Library" "18:31:58.5145698","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{DE68F9EC-CBEC-416E-9719-6923F0128D76}\1.0\FLAGS","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.5149240","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{DE68F9EC-CBEC-416E-9719-6923F0128D76}\1.0\FLAGS\(Default)","SUCCESS","Type: REG_SZ, Length: 4, Data: 0" "18:31:58.5153101","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{DE68F9EC-CBEC-416E-9719-6923F0128D76}\1.0\0","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.5157378","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{DE68F9EC-CBEC-416E-9719-6923F0128D76}\1.0\0\win32","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.5160876","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{DE68F9EC-CBEC-416E-9719-6923F0128D76}\1.0\0\win32\(Default)","SUCCESS","Type: REG_SZ, Length: 48, Data: D:\setup\HPeSupport.dll" "18:31:58.5164583","hpzwup01.exe","3936","RegCreateKey","HKCR\TypeLib\{DE68F9EC-CBEC-416E-9719-6923F0128D76}\1.0\HELPDIR","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.5168631","hpzwup01.exe","3936","RegSetValue","HKCR\TypeLib\{DE68F9EC-CBEC-416E-9719-6923F0128D76}\1.0\HELPDIR\(Default)","SUCCESS","Type: REG_SZ, Length: 20, Data: D:\setup\" "18:31:58.5174917","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{9BE2066D-5E51-4C15-B358-9EE4FEC47DDA}","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.5197699","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{9BE2066D-5E51-4C15-B358-9EE4FEC47DDA}\(Default)","SUCCESS","Type: REG_SZ, Length: 22, Data: IHPStamper" "18:31:58.5201202","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{9BE2066D-5E51-4C15-B358-9EE4FEC47DDA}\ProxyStubClsid","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.5204664","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{9BE2066D-5E51-4C15-B358-9EE4FEC47DDA}\ProxyStubClsid\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:58.5210111","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{9BE2066D-5E51-4C15-B358-9EE4FEC47DDA}\ProxyStubClsid32","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.5214693","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{9BE2066D-5E51-4C15-B358-9EE4FEC47DDA}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:58.5218529","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{9BE2066D-5E51-4C15-B358-9EE4FEC47DDA}\TypeLib","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.5222951","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{9BE2066D-5E51-4C15-B358-9EE4FEC47DDA}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {DE68F9EC-CBEC-416E-9719-6923F0128D76}" "18:31:58.5226055","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{9BE2066D-5E51-4C15-B358-9EE4FEC47DDA}\TypeLib\Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:58.5230946","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{23928D35-2D73-4276-97E8-A4835FE231E4}","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.5234740","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{23928D35-2D73-4276-97E8-A4835FE231E4}\(Default)","SUCCESS","Type: REG_SZ, Length: 24, Data: IHPStamper2" "18:31:58.5238425","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{23928D35-2D73-4276-97E8-A4835FE231E4}\ProxyStubClsid","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.5242196","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{23928D35-2D73-4276-97E8-A4835FE231E4}\ProxyStubClsid\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:58.5245624","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{23928D35-2D73-4276-97E8-A4835FE231E4}\ProxyStubClsid32","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.5250270","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{23928D35-2D73-4276-97E8-A4835FE231E4}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {00020424-0000-0000-C000-000000000046}" "18:31:58.5254083","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{23928D35-2D73-4276-97E8-A4835FE231E4}\TypeLib","SUCCESS","Desired Access: Maximum Allowed" "18:31:58.5258156","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{23928D35-2D73-4276-97E8-A4835FE231E4}\TypeLib\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {DE68F9EC-CBEC-416E-9719-6923F0128D76}" "18:31:58.5261232","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{23928D35-2D73-4276-97E8-A4835FE231E4}\TypeLib\Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 1.0" "18:31:58.9385097","hpzwup01.exe","3936","RegCreateKey","HKCU\SOFTWARE\Hewlett-Packard\HPeSupport","SUCCESS","Desired Access: Read" "18:31:58.9387908","hpzwup01.exe","3936","RegCreateKey","HKCU\SOFTWARE\Hewlett-Packard\HPeSupport","SUCCESS","Desired Access: All Access" "18:31:58.9389366","hpzwup01.exe","3936","RegCreateKey","HKCU\SOFTWARE\Hewlett-Packard\HPeSupport","SUCCESS","Desired Access: All Access" "18:31:58.9390414","hpzwup01.exe","3936","RegCreateKey","HKCU\SOFTWARE\Hewlett-Packard\HPeSupport","SUCCESS","Desired Access: Read" "18:31:58.9391975","hpzwup01.exe","3936","RegCreateKey","HKCU\SOFTWARE\Hewlett-Packard\HPeSupport","SUCCESS","Desired Access: All Access" "18:31:58.9392567","hpzwup01.exe","3936","RegSetValue","HKCU\Software\Hewlett-Packard\HPeSupport\SessionIDData9400","SUCCESS","Type: REG_SZ, Length: 74, Data: EJGmC4GwN7DbT7LmN6XmUdTrS30nBcLuPI0W" "18:31:58.9393241","hpzwup01.exe","3936","RegCreateKey","HKCU\SOFTWARE\Hewlett-Packard\HPeSupport","SUCCESS","Desired Access: All Access" "18:31:58.9393677","hpzwup01.exe","3936","RegSetValue","HKCU\Software\Hewlett-Packard\HPeSupport\Last9400","SUCCESS","Type: REG_DWORD, Length: 4, Data: 2008112418" "18:31:58.9404910","hpzwup01.exe","3936","RegCreateKey","HKCU\SOFTWARE\Hewlett-Packard\HPeSupport","SUCCESS","Desired Access: All Access" "18:31:58.9405368","hpzwup01.exe","3936","RegSetValue","HKCU\Software\Hewlett-Packard\HPeSupport\CurrentModuleData9400","SUCCESS","Type: REG_SZ, Length: 106, Data: UqOuGqGnGZCoBJGtGJ0jD352HYr2C3CnBJasC3KrHaP6GKGuGdqW" "18:31:58.9406416","hpzwup01.exe","3936","RegCreateKey","HKCU\SOFTWARE\Hewlett-Packard\HPeSupport","SUCCESS","Desired Access: Read" "18:31:58.9408215","hpzwup01.exe","3936","RegCreateKey","HKCU\SOFTWARE\Hewlett-Packard\HPeSupport","SUCCESS","Desired Access: All Access" "18:31:58.9409209","hpzwup01.exe","3936","RegCreateKey","HKCU\SOFTWARE\Hewlett-Packard\HPeSupport","SUCCESS","Desired Access: Read" "18:32:00.1377398","hpzwup01.exe","3936","RegCreateKey","HKCU\SOFTWARE\Hewlett-Packard\HPeSupport","SUCCESS","Desired Access: Read" "18:32:00.1385709","hpzwup01.exe","3936","RegCreateKey","HKCU\SOFTWARE\Hewlett-Packard\HPeSupport","SUCCESS","Desired Access: All Access" "18:32:00.1387447","hpzwup01.exe","3936","RegCreateKey","HKCU\SOFTWARE\Hewlett-Packard\HPeSupport","SUCCESS","Desired Access: All Access" "18:32:00.1388757","hpzwup01.exe","3936","RegCreateKey","HKCU\SOFTWARE\Hewlett-Packard\HPeSupport","SUCCESS","Desired Access: Read" "18:32:00.1390143","hpzwup01.exe","3936","RegCreateKey","HKCU\SOFTWARE\Hewlett-Packard\HPeSupport","SUCCESS","Desired Access: All Access" "18:32:00.1390992","hpzwup01.exe","3936","RegCreateKey","HKCU\SOFTWARE\Hewlett-Packard\HPeSupport","SUCCESS","Desired Access: Read" "18:32:11.8671509","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","" "18:32:12.4302610","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","" "18:32:12.4314808","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\Implemented Categories","SUCCESS","" "18:32:12.4404040","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.HPObjectInstaller.1\CLSID","SUCCESS","" "18:32:12.4431850","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.HPObjectInstaller.1","SUCCESS","" "18:32:12.4456395","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.HPObjectInstaller\CLSID","SUCCESS","" "18:32:12.4464885","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.HPObjectInstaller\CurVer","SUCCESS","" "18:32:12.4471914","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.HPObjectInstaller","SUCCESS","" "18:32:12.4477532","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\ProgID","SUCCESS","" "18:32:12.4481977","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\VersionIndependentProgID","SUCCESS","" "18:32:12.4508997","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\Programmable","SUCCESS","" "18:32:12.4514492","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\InprocServer32\ThreadingModel","SUCCESS","" "18:32:12.4537654","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\InprocServer32","SUCCESS","" "18:32:12.4540523","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\AppID","SUCCESS","" "18:32:12.4549790","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}\TypeLib","SUCCESS","" "18:32:12.4558361","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{9B17FE0E-51F2-4692-8B32-8EFB805FC0E7}","SUCCESS","" "18:32:12.4618779","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.VersionInfo.1\CLSID","SUCCESS","" "18:32:12.4635329","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.VersionInfo.1","SUCCESS","" "18:32:12.4646115","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.VersionInfo\CLSID","SUCCESS","" "18:32:12.4654334","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.VersionInfo\CurVer","SUCCESS","" "18:32:12.4656949","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.VersionInfo","SUCCESS","" "18:32:12.4668425","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{FDAD9D00-18C0-4578-9305-D711951FDF00}\ProgID","SUCCESS","" "18:32:12.4676859","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{FDAD9D00-18C0-4578-9305-D711951FDF00}\VersionIndependentProgID","SUCCESS","" "18:32:12.4685374","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{FDAD9D00-18C0-4578-9305-D711951FDF00}\Programmable","SUCCESS","" "18:32:12.4689154","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{FDAD9D00-18C0-4578-9305-D711951FDF00}\InprocServer32\ThreadingModel","SUCCESS","" "18:32:12.4691967","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{FDAD9D00-18C0-4578-9305-D711951FDF00}\InprocServer32","SUCCESS","" "18:32:12.4695149","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{FDAD9D00-18C0-4578-9305-D711951FDF00}\AppID","SUCCESS","" "18:32:12.4704011","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{FDAD9D00-18C0-4578-9305-D711951FDF00}\TypeLib","SUCCESS","" "18:32:12.4707779","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{FDAD9D00-18C0-4578-9305-D711951FDF00}","SUCCESS","" "18:32:12.4721055","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","" "18:32:12.4733087","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","" "18:32:12.4738454","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\Implemented Categories","SUCCESS","" "18:32:12.4796891","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.Status.1\CLSID","SUCCESS","" "18:32:12.4810918","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.Status.1","SUCCESS","" "18:32:12.4822218","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.Status\CLSID","SUCCESS","" "18:32:12.4830141","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.Status\CurVer","SUCCESS","" "18:32:12.4836916","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.Status","SUCCESS","" "18:32:12.4847786","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\ProgID","SUCCESS","" "18:32:12.4856203","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\VersionIndependentProgID","SUCCESS","" "18:32:12.4859706","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\Programmable","SUCCESS","" "18:32:12.4866660","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\InprocServer32\ThreadingModel","SUCCESS","" "18:32:12.4868945","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\InprocServer32","SUCCESS","" "18:32:12.4873177","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\AppID","SUCCESS","" "18:32:12.4876918","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}\TypeLib","SUCCESS","" "18:32:12.4884480","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{D9406D30-E93B-4EB5-97BA-4DE352A5C22E}","SUCCESS","" "18:32:12.4893778","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","" "18:32:12.4920404","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}\Implemented Categories","SUCCESS","" "18:32:12.4966787","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.HPInternet.1\CLSID","SUCCESS","" "18:32:12.4983110","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.HPInternet.1","SUCCESS","" "18:32:12.4993204","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.HPInternet\CLSID","SUCCESS","" "18:32:12.5006110","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.HPInternet\CurVer","SUCCESS","" "18:32:12.5008281","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.HPInternet","SUCCESS","" "18:32:12.5018738","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}\ProgID","SUCCESS","" "18:32:12.5027197","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}\VersionIndependentProgID","SUCCESS","" "18:32:12.5037589","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}\Programmable","SUCCESS","" "18:32:12.5041369","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}\InprocServer32\ThreadingModel","SUCCESS","" "18:32:12.5048364","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}\InprocServer32","SUCCESS","" "18:32:12.5051155","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}\AppID","SUCCESS","" "18:32:12.5054402","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}\TypeLib","SUCCESS","" "18:32:12.5061548","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{7B72AF68-E985-4136-A325-D1BC8326DFE4}","SUCCESS","" "18:32:12.5069110","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","" "18:32:12.5086129","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","" "18:32:12.5091619","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\Implemented Categories","SUCCESS","" "18:32:12.5171053","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.Settings.1\CLSID","SUCCESS","" "18:32:12.5179705","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.Settings.1","SUCCESS","" "18:32:12.5192629","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.Settings\CLSID","SUCCESS","" "18:32:12.5202621","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.Settings\CurVer","SUCCESS","" "18:32:12.5204789","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPCommunication.Settings","SUCCESS","" "18:32:12.5210329","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\ProgID","SUCCESS","" "18:32:12.5219319","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\VersionIndependentProgID","SUCCESS","" "18:32:12.5229047","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\Programmable","SUCCESS","" "18:32:12.5233623","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\InprocServer32\ThreadingModel","SUCCESS","" "18:32:12.5240540","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\InprocServer32","SUCCESS","" "18:32:12.5419697","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\AppID","SUCCESS","" "18:32:12.5425284","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}\TypeLib","SUCCESS","" "18:32:12.5427851","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{29A296F0-F0B9-4A6F-A9BE-F647A394849F}","SUCCESS","" "18:32:12.6318017","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{5656DD74-990F-41E8-BBB2-3D28CF936BA4}\1.0\0\win32","SUCCESS","" "18:32:12.6321895","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{5656DD74-990F-41E8-BBB2-3D28CF936BA4}\1.0\0","SUCCESS","" "18:32:12.6330508","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{5656DD74-990F-41E8-BBB2-3D28CF936BA4}\1.0\FLAGS","SUCCESS","" "18:32:12.6335092","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{5656DD74-990F-41E8-BBB2-3D28CF936BA4}\1.0\HELPDIR","SUCCESS","" "18:32:12.6338014","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{5656DD74-990F-41E8-BBB2-3D28CF936BA4}\1.0","SUCCESS","" "18:32:12.6340853","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{5656DD74-990F-41E8-BBB2-3D28CF936BA4}","SUCCESS","" "18:32:12.6361665","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{AC823880-A980-4254-9DDA-B76BC372EAEA}\ProxyStubClsid","SUCCESS","" "18:32:12.6366132","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{AC823880-A980-4254-9DDA-B76BC372EAEA}\ProxyStubClsid32","SUCCESS","" "18:32:12.6372337","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{AC823880-A980-4254-9DDA-B76BC372EAEA}\TypeLib","SUCCESS","" "18:32:12.6388314","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{AC823880-A980-4254-9DDA-B76BC372EAEA}","SUCCESS","" "18:32:12.6428883","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{CF0C7C80-6436-4CE0-AA17-7C8854DAB851}\ProxyStubClsid","SUCCESS","" "18:32:12.6433775","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{CF0C7C80-6436-4CE0-AA17-7C8854DAB851}\ProxyStubClsid32","SUCCESS","" "18:32:12.6438541","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{CF0C7C80-6436-4CE0-AA17-7C8854DAB851}\TypeLib","SUCCESS","" "18:32:12.6449140","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{CF0C7C80-6436-4CE0-AA17-7C8854DAB851}","SUCCESS","" "18:32:12.6460851","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{E2CEDDD6-8597-464B-86FA-96B2001E5D9D}\ProxyStubClsid","SUCCESS","" "18:32:12.6467059","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{E2CEDDD6-8597-464B-86FA-96B2001E5D9D}\ProxyStubClsid32","SUCCESS","" "18:32:12.6471503","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{E2CEDDD6-8597-464B-86FA-96B2001E5D9D}\TypeLib","SUCCESS","" "18:32:12.6475521","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{E2CEDDD6-8597-464B-86FA-96B2001E5D9D}","SUCCESS","" "18:32:12.6490408","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{C43FA267-76BC-4541-BD61-25354CDE8BEF}\ProxyStubClsid","SUCCESS","" "18:32:12.6495101","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{C43FA267-76BC-4541-BD61-25354CDE8BEF}\ProxyStubClsid32","SUCCESS","" "18:32:12.6500069","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{C43FA267-76BC-4541-BD61-25354CDE8BEF}\TypeLib","SUCCESS","" "18:32:12.6502692","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{C43FA267-76BC-4541-BD61-25354CDE8BEF}","SUCCESS","" "18:32:12.6509528","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{AB19FFEE-58E6-4D42-98BC-962631B59FEA}\ProxyStubClsid","SUCCESS","" "18:32:12.6515741","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{AB19FFEE-58E6-4D42-98BC-962631B59FEA}\ProxyStubClsid32","SUCCESS","" "18:32:12.6521121","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{AB19FFEE-58E6-4D42-98BC-962631B59FEA}\TypeLib","SUCCESS","" "18:32:12.6523784","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{AB19FFEE-58E6-4D42-98BC-962631B59FEA}","SUCCESS","" "18:32:12.6530223","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{F152DBC9-CC75-414A-98CF-4B2E0D200D17}\ProxyStubClsid","SUCCESS","" "18:32:12.6567734","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{F152DBC9-CC75-414A-98CF-4B2E0D200D17}\ProxyStubClsid32","SUCCESS","" "18:32:12.6572997","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{F152DBC9-CC75-414A-98CF-4B2E0D200D17}\TypeLib","SUCCESS","" "18:32:12.6575765","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{F152DBC9-CC75-414A-98CF-4B2E0D200D17}","SUCCESS","" "18:32:12.6582825","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{F2D9F02A-20E9-44C2-953D-33535D7C54D8}\ProxyStubClsid","SUCCESS","" "18:32:12.6587186","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{F2D9F02A-20E9-44C2-953D-33535D7C54D8}\ProxyStubClsid32","SUCCESS","" "18:32:12.6591957","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{F2D9F02A-20E9-44C2-953D-33535D7C54D8}\TypeLib","SUCCESS","" "18:32:12.6594706","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{F2D9F02A-20E9-44C2-953D-33535D7C54D8}","SUCCESS","" "18:32:12.6701038","hpzwup01.exe","3936","RegDeleteKey","HKCR\AppID\{11BC7FC2-0F43-4226-B89B-30B06D81002E}","SUCCESS","" "18:32:12.6721625","hpzwup01.exe","3936","RegDeleteValue","HKCR\AppID\HPCommunication.DLL\AppID","SUCCESS","" "18:32:12.6796475","hpzwup01.exe","3936","RegDeleteKey","HKCR\AppID\HPCommunication.DLL","SUCCESS","" "18:32:12.7087886","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPScripting.HPScript.1\CLSID","SUCCESS","" "18:32:12.7092630","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPScripting.HPScript.1","SUCCESS","" "18:32:12.7097128","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPScripting.HPScript\CLSID","SUCCESS","" "18:32:12.7100335","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPScripting.HPScript\CurVer","SUCCESS","" "18:32:12.7102980","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPScripting.HPScript","SUCCESS","" "18:32:12.7108227","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}\ProgID","SUCCESS","" "18:32:12.7111970","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}\VersionIndependentProgID","SUCCESS","" "18:32:12.7116038","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}\Programmable","SUCCESS","" "18:32:12.7120013","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}\InprocServer32\ThreadingModel","SUCCESS","" "18:32:12.7122396","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}\InprocServer32","SUCCESS","" "18:32:12.7126056","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}\AppID","SUCCESS","" "18:32:12.7129330","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}\TypeLib","SUCCESS","" "18:32:12.7139189","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{5E6F22B3-7DF6-4C64-8AD0-1A6CC1351085}","SUCCESS","" "18:32:12.7254259","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{5BDB390C-CF8B-4985-A227-F84FB6EBDD3D}\1.0\0\win32","SUCCESS","" "18:32:12.7264361","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{5BDB390C-CF8B-4985-A227-F84FB6EBDD3D}\1.0\0","SUCCESS","" "18:32:12.7272527","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{5BDB390C-CF8B-4985-A227-F84FB6EBDD3D}\1.0\FLAGS","SUCCESS","" "18:32:12.7277139","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{5BDB390C-CF8B-4985-A227-F84FB6EBDD3D}\1.0\HELPDIR","SUCCESS","" "18:32:12.7285372","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{5BDB390C-CF8B-4985-A227-F84FB6EBDD3D}\1.0","SUCCESS","" "18:32:12.7288233","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{5BDB390C-CF8B-4985-A227-F84FB6EBDD3D}","SUCCESS","" "18:32:12.7296044","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{530DD015-887B-497D-A9B4-B57334C06D14}\ProxyStubClsid","SUCCESS","" "18:32:12.7305984","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{530DD015-887B-497D-A9B4-B57334C06D14}\ProxyStubClsid32","SUCCESS","" "18:32:12.7328724","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{530DD015-887B-497D-A9B4-B57334C06D14}\TypeLib","SUCCESS","" "18:32:12.7333152","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{530DD015-887B-497D-A9B4-B57334C06D14}","SUCCESS","" "18:32:12.7406371","hpzwup01.exe","3936","RegDeleteKey","HKCR\AppID\{C0359F8F-FC4F-4292-A4B3-C3B3C60DE57B}","SUCCESS","" "18:32:12.7411293","hpzwup01.exe","3936","RegDeleteValue","HKCR\AppID\HPScripting.DLL\AppID","SUCCESS","" "18:32:12.7413537","hpzwup01.exe","3936","RegDeleteKey","HKCR\AppID\HPScripting.DLL","SUCCESS","" "18:32:12.7475952","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPInternetUtil.InetCollection.1\CLSID","SUCCESS","" "18:32:12.7486931","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPInternetUtil.InetCollection.1","SUCCESS","" "18:32:12.7496162","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPInternetUtil.InetCollection\CLSID","SUCCESS","" "18:32:12.7504688","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPInternetUtil.InetCollection\CurVer","SUCCESS","" "18:32:12.7506858","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPInternetUtil.InetCollection","SUCCESS","" "18:32:12.7517737","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{36385AE6-F389-41E3-97DF-7412F61418F8}\ProgID","SUCCESS","" "18:32:12.7531613","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{36385AE6-F389-41E3-97DF-7412F61418F8}\VersionIndependentProgID","SUCCESS","" "18:32:12.7535672","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{36385AE6-F389-41E3-97DF-7412F61418F8}\Programmable","SUCCESS","" "18:32:12.7539567","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{36385AE6-F389-41E3-97DF-7412F61418F8}\InprocServer32\ThreadingModel","SUCCESS","" "18:32:12.7541913","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{36385AE6-F389-41E3-97DF-7412F61418F8}\InprocServer32","SUCCESS","" "18:32:12.7545288","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{36385AE6-F389-41E3-97DF-7412F61418F8}\AppID","SUCCESS","" "18:32:12.7548886","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{36385AE6-F389-41E3-97DF-7412F61418F8}\TypeLib","SUCCESS","" "18:32:12.7551194","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{36385AE6-F389-41E3-97DF-7412F61418F8}","SUCCESS","" "18:32:12.7601153","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPInternetUtil.InetFile.1\CLSID","SUCCESS","" "18:32:12.7609249","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPInternetUtil.InetFile.1","SUCCESS","" "18:32:12.7621708","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPInternetUtil.InetFile\CLSID","SUCCESS","" "18:32:12.7645714","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPInternetUtil.InetFile\CurVer","SUCCESS","" "18:32:12.7648276","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPInternetUtil.InetFile","SUCCESS","" "18:32:12.7661071","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{7DB9052D-4CDD-45F7-9EDF-8FE44F19678B}\ProgID","SUCCESS","" "18:32:12.7669496","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{7DB9052D-4CDD-45F7-9EDF-8FE44F19678B}\VersionIndependentProgID","SUCCESS","" "18:32:12.7679545","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{7DB9052D-4CDD-45F7-9EDF-8FE44F19678B}\Programmable","SUCCESS","" "18:32:12.7683867","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{7DB9052D-4CDD-45F7-9EDF-8FE44F19678B}\InprocServer32\ThreadingModel","SUCCESS","" "18:32:12.7686247","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{7DB9052D-4CDD-45F7-9EDF-8FE44F19678B}\InprocServer32","SUCCESS","" "18:32:12.7689016","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{7DB9052D-4CDD-45F7-9EDF-8FE44F19678B}\AppID","SUCCESS","" "18:32:12.7693810","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{7DB9052D-4CDD-45F7-9EDF-8FE44F19678B}\TypeLib","SUCCESS","" "18:32:12.7702679","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{7DB9052D-4CDD-45F7-9EDF-8FE44F19678B}","SUCCESS","" "18:32:12.7753130","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPInternetUtil.InetService.1\CLSID","SUCCESS","" "18:32:12.7760664","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPInternetUtil.InetService.1","SUCCESS","" "18:32:12.7765715","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPInternetUtil.InetService\CLSID","SUCCESS","" "18:32:12.7777010","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPInternetUtil.InetService\CurVer","SUCCESS","" "18:32:12.7786143","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPInternetUtil.InetService","SUCCESS","" "18:32:12.7791498","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\ProgID","SUCCESS","" "18:32:12.7806955","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\VersionIndependentProgID","SUCCESS","" "18:32:12.7816772","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\Programmable","SUCCESS","" "18:32:12.7821563","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\InprocServer32\ThreadingModel","SUCCESS","" "18:32:12.7827072","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\InprocServer32","SUCCESS","" "18:32:12.7830355","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\AppID","SUCCESS","" "18:32:12.7834110","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\Control","SUCCESS","" "18:32:12.7837498","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\ToolboxBitmap32","SUCCESS","" "18:32:12.7847949","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\MiscStatus\1","SUCCESS","" "18:32:12.7865868","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\MiscStatus","SUCCESS","" "18:32:12.7874131","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\TypeLib","SUCCESS","" "18:32:12.7882348","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}\Version","SUCCESS","" "18:32:12.7891740","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{6D84BC07-7979-4E59-9589-17E1E5A8FF55}","SUCCESS","" "18:32:12.7906677","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{B4079907-CE55-44E7-961D-BFA47DD2EBDC}\1.0\0\win32","SUCCESS","" "18:32:12.7915466","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{B4079907-CE55-44E7-961D-BFA47DD2EBDC}\1.0\0","SUCCESS","" "18:32:12.7923945","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{B4079907-CE55-44E7-961D-BFA47DD2EBDC}\1.0\FLAGS","SUCCESS","" "18:32:12.7933214","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{B4079907-CE55-44E7-961D-BFA47DD2EBDC}\1.0\HELPDIR","SUCCESS","" "18:32:12.7944341","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{B4079907-CE55-44E7-961D-BFA47DD2EBDC}\1.0","SUCCESS","" "18:32:12.7954748","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{B4079907-CE55-44E7-961D-BFA47DD2EBDC}","SUCCESS","" "18:32:12.7973915","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{805150DC-53E0-40DD-99E1-A9F9CEC2E53C}\ProxyStubClsid","SUCCESS","" "18:32:12.7984525","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{805150DC-53E0-40DD-99E1-A9F9CEC2E53C}\ProxyStubClsid32","SUCCESS","" "18:32:12.7993649","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{805150DC-53E0-40DD-99E1-A9F9CEC2E53C}\TypeLib","SUCCESS","" "18:32:12.7996767","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{805150DC-53E0-40DD-99E1-A9F9CEC2E53C}","SUCCESS","" "18:32:12.8010540","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{9ED1A2E2-8A49-4871-B998-FE012390ED3F}\ProxyStubClsid","SUCCESS","" "18:32:12.8020256","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{9ED1A2E2-8A49-4871-B998-FE012390ED3F}\ProxyStubClsid32","SUCCESS","" "18:32:12.8027008","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{9ED1A2E2-8A49-4871-B998-FE012390ED3F}\TypeLib","SUCCESS","" "18:32:12.8034437","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{9ED1A2E2-8A49-4871-B998-FE012390ED3F}","SUCCESS","" "18:32:12.8047785","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{0154DB4A-05FA-41AC-A117-FAEB893D483D}\ProxyStubClsid","SUCCESS","" "18:32:12.8053372","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{0154DB4A-05FA-41AC-A117-FAEB893D483D}\ProxyStubClsid32","SUCCESS","" "18:32:12.8057906","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{0154DB4A-05FA-41AC-A117-FAEB893D483D}\TypeLib","SUCCESS","" "18:32:12.8061208","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{0154DB4A-05FA-41AC-A117-FAEB893D483D}","SUCCESS","" "18:32:12.8073970","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{B8DCC1F7-D1E4-4224-9D9F-141C557BDF78}\ProxyStubClsid","SUCCESS","" "18:32:12.8088807","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{B8DCC1F7-D1E4-4224-9D9F-141C557BDF78}\ProxyStubClsid32","SUCCESS","" "18:32:12.8094528","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{B8DCC1F7-D1E4-4224-9D9F-141C557BDF78}\TypeLib","SUCCESS","" "18:32:12.8098557","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{B8DCC1F7-D1E4-4224-9D9F-141C557BDF78}","SUCCESS","" "18:32:12.8154044","hpzwup01.exe","3936","RegDeleteKey","HKCR\AppID\{DC49F5B4-E4EB-4ED4-A15B-26FE03C9B7E7}","SUCCESS","" "18:32:12.8165018","hpzwup01.exe","3936","RegDeleteValue","HKCR\AppID\InternetUtil.DLL\AppID","SUCCESS","" "18:32:12.8171926","hpzwup01.exe","3936","RegDeleteKey","HKCR\AppID\InternetUtil.DLL","SUCCESS","" "18:32:12.8182900","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","" "18:32:12.8194236","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","" "18:32:12.8200609","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}\Implemented Categories","SUCCESS","" "18:32:12.8246690","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ScriptUtil.1\CLSID","SUCCESS","" "18:32:12.8249137","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ScriptUtil.1","SUCCESS","" "18:32:12.8683016","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ScriptUtil\CLSID","SUCCESS","" "18:32:12.8688925","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ScriptUtil\CurVer","SUCCESS","" "18:32:12.8691277","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ScriptUtil","SUCCESS","" "18:32:12.8729514","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}\ProgID","SUCCESS","" "18:32:12.8734221","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}\VersionIndependentProgID","SUCCESS","" "18:32:12.8737987","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}\Programmable","SUCCESS","" "18:32:12.8741814","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}\InprocServer32\ThreadingModel","SUCCESS","" "18:32:12.8745309","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}\InprocServer32","SUCCESS","" "18:32:12.8748206","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}\AppID","SUCCESS","" "18:32:12.8751528","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}\TypeLib","SUCCESS","" "18:32:12.8753802","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{DF1F1C17-6A29-45fb-A3C6-9825908E062E}","SUCCESS","" "18:32:12.8805269","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.Content.1\CLSID","SUCCESS","" "18:32:12.8814544","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.Content.1","SUCCESS","" "18:32:12.8825554","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.Content\CLSID","SUCCESS","" "18:32:12.8834404","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.Content\CurVer","SUCCESS","" "18:32:12.8842715","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.Content","SUCCESS","" "18:32:12.8853010","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{5A494E87-262C-4340-A539-2FAC0A85D935}\ProgID","SUCCESS","" "18:32:12.8861313","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{5A494E87-262C-4340-A539-2FAC0A85D935}\VersionIndependentProgID","SUCCESS","" "18:32:12.8870442","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{5A494E87-262C-4340-A539-2FAC0A85D935}\Programmable","SUCCESS","" "18:32:12.8874306","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{5A494E87-262C-4340-A539-2FAC0A85D935}\InprocServer32\ThreadingModel","SUCCESS","" "18:32:12.8876642","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{5A494E87-262C-4340-A539-2FAC0A85D935}\InprocServer32","SUCCESS","" "18:32:12.8883134","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{5A494E87-262C-4340-A539-2FAC0A85D935}\AppID","SUCCESS","" "18:32:12.8886478","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{5A494E87-262C-4340-A539-2FAC0A85D935}\TypeLib","SUCCESS","" "18:32:12.8906751","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{5A494E87-262C-4340-A539-2FAC0A85D935}","SUCCESS","" "18:32:12.8954193","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentProduct.1\CLSID","SUCCESS","" "18:32:12.8962583","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentProduct.1","SUCCESS","" "18:32:12.8972151","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentProduct\CLSID","SUCCESS","" "18:32:12.8984884","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentProduct\CurVer","SUCCESS","" "18:32:12.8992220","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentProduct","SUCCESS","" "18:32:12.9002423","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}\ProgID","SUCCESS","" "18:32:12.9010619","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}\VersionIndependentProgID","SUCCESS","" "18:32:12.9022523","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}\Programmable","SUCCESS","" "18:32:12.9026418","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}\InprocServer32\ThreadingModel","SUCCESS","" "18:32:12.9029767","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}\InprocServer32","SUCCESS","" "18:32:12.9032656","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}\AppID","SUCCESS","" "18:32:12.9037100","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}\TypeLib","SUCCESS","" "18:32:12.9045713","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{9986CC36-7FA8-4E9A-ADE1-E197FCC5484B}","SUCCESS","" "18:32:12.9092038","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentOS.1\CLSID","SUCCESS","" "18:32:12.9100215","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentOS.1","SUCCESS","" "18:32:12.9110275","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentOS\CLSID","SUCCESS","" "18:32:12.9118334","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentOS\CurVer","SUCCESS","" "18:32:12.9131875","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentOS","SUCCESS","" "18:32:12.9144768","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{294E9835-D0F1-4815-8C52-3C08FBB1403E}\ProgID","SUCCESS","" "18:32:12.9152867","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{294E9835-D0F1-4815-8C52-3C08FBB1403E}\VersionIndependentProgID","SUCCESS","" "18:32:12.9163318","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{294E9835-D0F1-4815-8C52-3C08FBB1403E}\Programmable","SUCCESS","" "18:32:12.9167536","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{294E9835-D0F1-4815-8C52-3C08FBB1403E}\InprocServer32\ThreadingModel","SUCCESS","" "18:32:12.9169913","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{294E9835-D0F1-4815-8C52-3C08FBB1403E}\InprocServer32","SUCCESS","" "18:32:12.9172732","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{294E9835-D0F1-4815-8C52-3C08FBB1403E}\AppID","SUCCESS","" "18:32:12.9176825","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{294E9835-D0F1-4815-8C52-3C08FBB1403E}\TypeLib","SUCCESS","" "18:32:12.9179538","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{294E9835-D0F1-4815-8C52-3C08FBB1403E}","SUCCESS","" "18:32:12.9230105","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentFile.1\CLSID","SUCCESS","" "18:32:12.9243412","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentFile.1","SUCCESS","" "18:32:12.9253402","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentFile\CLSID","SUCCESS","" "18:32:12.9263288","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentFile\CurVer","SUCCESS","" "18:32:12.9270141","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentFile","SUCCESS","" "18:32:12.9275382","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{684E4896-6EFC-4A3D-B967-6105894A6796}\ProgID","SUCCESS","" "18:32:12.9284070","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{684E4896-6EFC-4A3D-B967-6105894A6796}\VersionIndependentProgID","SUCCESS","" "18:32:12.9293373","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{684E4896-6EFC-4A3D-B967-6105894A6796}\Programmable","SUCCESS","" "18:32:12.9297226","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{684E4896-6EFC-4A3D-B967-6105894A6796}\InprocServer32\ThreadingModel","SUCCESS","" "18:32:12.9301369","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{684E4896-6EFC-4A3D-B967-6105894A6796}\InprocServer32","SUCCESS","" "18:32:12.9308241","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{684E4896-6EFC-4A3D-B967-6105894A6796}\AppID","SUCCESS","" "18:32:12.9311660","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{684E4896-6EFC-4A3D-B967-6105894A6796}\TypeLib","SUCCESS","" "18:32:12.9320120","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{684E4896-6EFC-4A3D-B967-6105894A6796}","SUCCESS","" "18:32:12.9328825","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","" "18:32:12.9340385","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","" "18:32:12.9345615","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\Implemented Categories","SUCCESS","" "18:32:12.9401624","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentCollection.1\CLSID","SUCCESS","" "18:32:12.9412006","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentCollection.1","SUCCESS","" "18:32:12.9416559","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentCollection\CLSID","SUCCESS","" "18:32:12.9425194","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentCollection\CurVer","SUCCESS","" "18:32:12.9431885","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentCollection","SUCCESS","" "18:32:12.9444795","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\ProgID","SUCCESS","" "18:32:12.9454469","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\VersionIndependentProgID","SUCCESS","" "18:32:12.9462532","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\Programmable","SUCCESS","" "18:32:12.9467337","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\InprocServer32\ThreadingModel","SUCCESS","" "18:32:12.9469672","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\InprocServer32","SUCCESS","" "18:32:12.9483956","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\AppID","SUCCESS","" "18:32:12.9488655","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}\TypeLib","SUCCESS","" "18:32:12.9491086","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{7CB9D4F5-C492-42A4-93B1-3F7D6946470D}","SUCCESS","" "18:32:12.9498779","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","" "18:32:12.9517092","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","" "18:32:12.9529836","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\Implemented Categories","SUCCESS","" "18:32:12.9581357","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentFinder.1\CLSID","SUCCESS","" "18:32:12.9583882","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentFinder.1","SUCCESS","" "18:32:12.9588738","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentFinder\CLSID","SUCCESS","" "18:32:12.9592110","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentFinder\CurVer","SUCCESS","" "18:32:12.9594490","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPRulesEngine.ContentFinder","SUCCESS","" "18:32:12.9600574","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\ProgID","SUCCESS","" "18:32:12.9604131","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\VersionIndependentProgID","SUCCESS","" "18:32:12.9607720","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\Programmable","SUCCESS","" "18:32:12.9612162","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\InprocServer32\ThreadingModel","SUCCESS","" "18:32:12.9614420","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\InprocServer32","SUCCESS","" "18:32:12.9617197","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\AppID","SUCCESS","" "18:32:12.9631860","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\Control","SUCCESS","" "18:32:12.9635827","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\ToolboxBitmap32","SUCCESS","" "18:32:12.9640454","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\MiscStatus\1","SUCCESS","" "18:32:12.9642934","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\MiscStatus","SUCCESS","" "18:32:12.9646868","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\TypeLib","SUCCESS","" "18:32:12.9650382","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\Version","SUCCESS","" "18:32:12.9654215","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}\Marcon","SUCCESS","" "18:32:12.9656528","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{BE65189A-4770-47A0-9B7B-68827DB1C317}","SUCCESS","" "18:32:12.9686728","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{C9C10E42-469E-436E-9216-9C6792BC8A70}\1.0\0\win32","SUCCESS","" "18:32:12.9690589","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{C9C10E42-469E-436E-9216-9C6792BC8A70}\1.0\0","SUCCESS","" "18:32:12.9698754","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{C9C10E42-469E-436E-9216-9C6792BC8A70}\1.0\FLAGS","SUCCESS","" "18:32:12.9704752","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{C9C10E42-469E-436E-9216-9C6792BC8A70}\1.0\HELPDIR","SUCCESS","" "18:32:12.9707387","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{C9C10E42-469E-436E-9216-9C6792BC8A70}\1.0","SUCCESS","" "18:32:12.9712915","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{C9C10E42-469E-436E-9216-9C6792BC8A70}","SUCCESS","" "18:32:12.9720355","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{DF4536A8-BF2D-4834-A454-8FAD9B120005}\ProxyStubClsid","SUCCESS","" "18:32:12.9724830","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{DF4536A8-BF2D-4834-A454-8FAD9B120005}\ProxyStubClsid32","SUCCESS","" "18:32:12.9729655","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{DF4536A8-BF2D-4834-A454-8FAD9B120005}\TypeLib","SUCCESS","" "18:32:12.9732538","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{DF4536A8-BF2D-4834-A454-8FAD9B120005}","SUCCESS","" "18:32:12.9739352","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{4C99B6E9-C553-4E2C-8402-C7D31291B32A}\ProxyStubClsid","SUCCESS","" "18:32:12.9744115","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{4C99B6E9-C553-4E2C-8402-C7D31291B32A}\ProxyStubClsid32","SUCCESS","" "18:32:12.9748903","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{4C99B6E9-C553-4E2C-8402-C7D31291B32A}\TypeLib","SUCCESS","" "18:32:12.9757217","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{4C99B6E9-C553-4E2C-8402-C7D31291B32A}","SUCCESS","" "18:32:12.9917360","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{ED9F739F-B63F-4D14-A555-F7F11F3FDCD9}\ProxyStubClsid","SUCCESS","" "18:32:12.9922551","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{ED9F739F-B63F-4D14-A555-F7F11F3FDCD9}\ProxyStubClsid32","SUCCESS","" "18:32:12.9926993","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{ED9F739F-B63F-4D14-A555-F7F11F3FDCD9}\TypeLib","SUCCESS","" "18:32:12.9929672","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{ED9F739F-B63F-4D14-A555-F7F11F3FDCD9}","SUCCESS","" "18:32:12.9936706","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{30F72035-66AE-45D9-A2A7-AC3FBADCE793}\ProxyStubClsid","SUCCESS","" "18:32:12.9947252","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{30F72035-66AE-45D9-A2A7-AC3FBADCE793}\ProxyStubClsid32","SUCCESS","" "18:32:12.9952018","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{30F72035-66AE-45D9-A2A7-AC3FBADCE793}\TypeLib","SUCCESS","" "18:32:12.9955594","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{30F72035-66AE-45D9-A2A7-AC3FBADCE793}","SUCCESS","" "18:32:12.9961995","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{4EE1F6B7-1C7A-46AF-AD5D-4BD3E9FB2CBE}\ProxyStubClsid","SUCCESS","" "18:32:12.9967719","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{4EE1F6B7-1C7A-46AF-AD5D-4BD3E9FB2CBE}\ProxyStubClsid32","SUCCESS","" "18:32:13.0138450","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{4EE1F6B7-1C7A-46AF-AD5D-4BD3E9FB2CBE}\TypeLib","SUCCESS","" "18:32:13.0142358","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{4EE1F6B7-1C7A-46AF-AD5D-4BD3E9FB2CBE}","SUCCESS","" "18:32:13.0149524","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{78D329A0-795E-46E2-86E1-5C13C930302D}\ProxyStubClsid","SUCCESS","" "18:32:13.0154108","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{78D329A0-795E-46E2-86E1-5C13C930302D}\ProxyStubClsid32","SUCCESS","" "18:32:13.0158598","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{78D329A0-795E-46E2-86E1-5C13C930302D}\TypeLib","SUCCESS","" "18:32:13.0161660","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{78D329A0-795E-46E2-86E1-5C13C930302D}","SUCCESS","" "18:32:13.0168736","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{FDD27BD5-AA4A-4A4C-9EB1-06F1E1BB2B63}\ProxyStubClsid","SUCCESS","" "18:32:13.0173868","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{FDD27BD5-AA4A-4A4C-9EB1-06F1E1BB2B63}\ProxyStubClsid32","SUCCESS","" "18:32:13.0178343","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{FDD27BD5-AA4A-4A4C-9EB1-06F1E1BB2B63}\TypeLib","SUCCESS","" "18:32:13.0180983","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{FDD27BD5-AA4A-4A4C-9EB1-06F1E1BB2B63}","SUCCESS","" "18:32:13.0188819","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{1F092142-2520-46F9-A293-EF85C72DCF74}\ProxyStubClsid","SUCCESS","" "18:32:13.0199977","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{1F092142-2520-46F9-A293-EF85C72DCF74}\ProxyStubClsid32","SUCCESS","" "18:32:13.0205229","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{1F092142-2520-46F9-A293-EF85C72DCF74}\TypeLib","SUCCESS","" "18:32:13.0207836","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{1F092142-2520-46F9-A293-EF85C72DCF74}","SUCCESS","" "18:32:13.0483673","hpzwup01.exe","3936","RegDeleteKey","HKCR\AppID\{3127F179-FE9E-4E8B-B009-4330342B89B7}","SUCCESS","" "18:32:13.0488299","hpzwup01.exe","3936","RegDeleteValue","HKCR\AppID\RulesEngine.DLL\AppID","SUCCESS","" "18:32:13.0491123","hpzwup01.exe","3936","RegDeleteKey","HKCR\AppID\RulesEngine.DLL","SUCCESS","" "18:32:13.0551854","hpzwup01.exe","3936","RegDeleteKey","HKCR\InstallMetrics.CInstallMetrics.1\CLSID","SUCCESS","" "18:32:13.0554383","hpzwup01.exe","3936","RegDeleteKey","HKCR\InstallMetrics.CInstallMetrics.1","SUCCESS","" "18:32:13.0559227","hpzwup01.exe","3936","RegDeleteKey","HKCR\InstallMetrics.CInstallMetrics\CLSID","SUCCESS","" "18:32:13.0562487","hpzwup01.exe","3936","RegDeleteKey","HKCR\InstallMetrics.CInstallMetrics\CurVer","SUCCESS","" "18:32:13.0564563","hpzwup01.exe","3936","RegDeleteKey","HKCR\InstallMetrics.CInstallMetrics","SUCCESS","" "18:32:13.0569410","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{D446CB6C-DEC5-4169-92D2-AF110CB78FF7}\ProgID","SUCCESS","" "18:32:13.0573617","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{D446CB6C-DEC5-4169-92D2-AF110CB78FF7}\VersionIndependentProgID","SUCCESS","" "18:32:13.0577184","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{D446CB6C-DEC5-4169-92D2-AF110CB78FF7}\Programmable","SUCCESS","" "18:32:13.0580920","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{D446CB6C-DEC5-4169-92D2-AF110CB78FF7}\InprocServer32\ThreadingModel","SUCCESS","" "18:32:13.0583560","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{D446CB6C-DEC5-4169-92D2-AF110CB78FF7}\InprocServer32","SUCCESS","" "18:32:13.0586529","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{D446CB6C-DEC5-4169-92D2-AF110CB78FF7}\AppID","SUCCESS","" "18:32:13.0590326","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{D446CB6C-DEC5-4169-92D2-AF110CB78FF7}\TypeLib","SUCCESS","" "18:32:13.0595536","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{D446CB6C-DEC5-4169-92D2-AF110CB78FF7}","SUCCESS","" "18:32:13.0730634","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{55676750-8EC2-4C6C-8717-F5984FC25275}\1.0\0\win32","SUCCESS","" "18:32:13.0734210","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{55676750-8EC2-4C6C-8717-F5984FC25275}\1.0\0","SUCCESS","" "18:32:13.0742809","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{55676750-8EC2-4C6C-8717-F5984FC25275}\1.0\FLAGS","SUCCESS","" "18:32:13.0747259","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{55676750-8EC2-4C6C-8717-F5984FC25275}\1.0\HELPDIR","SUCCESS","" "18:32:13.0749832","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{55676750-8EC2-4C6C-8717-F5984FC25275}\1.0","SUCCESS","" "18:32:13.0754579","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{55676750-8EC2-4C6C-8717-F5984FC25275}","SUCCESS","" "18:32:13.0761736","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\NumMethods","SUCCESS","" "18:32:13.0777953","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\ProxyStubClsid","SUCCESS","" "18:32:13.0782942","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\ProxyStubClsid32","SUCCESS","" "18:32:13.0787817","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\TypeLib","SUCCESS","" "18:32:13.0790790","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}","SUCCESS","" "18:32:13.0881206","hpzwup01.exe","3936","RegDeleteKey","HKCR\AppID\{2F16B25F-1B36-4B7B-A972-4C56E7F04AC5}","SUCCESS","" "18:32:13.0886229","hpzwup01.exe","3936","RegDeleteValue","HKCR\AppID\InstallMetrics.DLL\AppID","SUCCESS","" "18:32:13.0888568","hpzwup01.exe","3936","RegDeleteKey","HKCR\AppID\InstallMetrics.DLL","SUCCESS","" "18:32:13.0892535","hpzwup01.exe","3936","RegCreateKey","HKCU\Software\Classes\CLSID","SUCCESS","Desired Access: Write" "18:32:13.0894281","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}","SUCCESS","Desired Access: Write" "18:32:13.0896133","hpzwup01.exe","3936","RegCreateKey","HKCR\CLSID\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\InProcServer32","SUCCESS","Desired Access: Write" "18:32:13.0897613","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\InProcServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 56, Data: D:\setup\InstallMetrics.dll" "18:32:13.0899656","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\InProcServer32\ThreadingModel","SUCCESS","Type: REG_SZ, Length: 10, Data: Both" "18:32:13.0901625","hpzwup01.exe","3936","RegSetValue","HKCR\CLSID\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\(Default)","SUCCESS","Type: REG_SZ, Length: 32, Data: PSFactoryBuffer" "18:32:13.0902977","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface","SUCCESS","Desired Access: Write" "18:32:13.0904606","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}","SUCCESS","Desired Access: Write" "18:32:13.1203510","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\ProxyStubClsid32","SUCCESS","Desired Access: Write" "18:32:13.1212031","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\ProxyStubClsid32\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {12E91406-2C17-43ED-8D2F-E1CAE7701DA9}" "18:32:13.1243456","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\(Default)","SUCCESS","Type: REG_SZ, Length: 34, Data: ICInstallMetrics" "18:32:13.1249365","hpzwup01.exe","3936","RegCreateKey","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\NumMethods","SUCCESS","Desired Access: Write" "18:32:13.1259595","hpzwup01.exe","3936","RegSetValue","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\NumMethods\(Default)","SUCCESS","Type: REG_SZ, Length: 6, Data: 19" "18:32:13.1276016","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\NumMethods","SUCCESS","" "18:32:13.1278483","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\ProxyStubClsid32","SUCCESS","" "18:32:13.1281721","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}","SUCCESS","" "18:32:13.1288906","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}\InProcServer32","SUCCESS","" "18:32:13.1291275","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{12E91406-2C17-43ED-8D2F-E1CAE7701DA9}","SUCCESS","" "18:32:13.1299765","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","" "18:32:13.1314083","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","" "18:32:13.1319703","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\Implemented Categories","SUCCESS","" "18:32:13.1392333","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPeSupport.HPStamper.1\CLSID","SUCCESS","" "18:32:13.1395026","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPeSupport.HPStamper.1","SUCCESS","" "18:32:13.1399487","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPeSupport.HPStamper\CLSID","SUCCESS","" "18:32:13.1402991","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPeSupport.HPStamper\CurVer","SUCCESS","" "18:32:13.1405217","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPeSupport.HPStamper","SUCCESS","" "18:32:13.1410257","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\ProgID","SUCCESS","" "18:32:13.1413889","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\VersionIndependentProgID","SUCCESS","" "18:32:13.1417758","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\Programmable","SUCCESS","" "18:32:13.1421512","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\InprocServer32\ThreadingModel","SUCCESS","" "18:32:13.1424647","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\InprocServer32","SUCCESS","" "18:32:13.1427840","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\AppID","SUCCESS","" "18:32:13.1431058","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}\TypeLib","SUCCESS","" "18:32:13.1433369","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{63B3EC14-9F70-4129-B935-46EFB37013E8}","SUCCESS","" "18:32:13.1440898","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","" "18:32:13.1446736","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}","SUCCESS","" "18:32:13.1452195","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\Implemented Categories","SUCCESS","" "18:32:13.1499757","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPeSupport.HPStamper2.1\CLSID","SUCCESS","" "18:32:13.1502132","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPeSupport.HPStamper2.1","SUCCESS","" "18:32:13.1507501","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPeSupport.HPStamper2\CLSID","SUCCESS","" "18:32:13.1510714","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPeSupport.HPStamper2\CurVer","SUCCESS","" "18:32:13.1514709","hpzwup01.exe","3936","RegDeleteKey","HKCR\HPeSupport.HPStamper2","SUCCESS","" "18:32:13.1520128","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\ProgID","SUCCESS","" "18:32:13.1523743","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\VersionIndependentProgID","SUCCESS","" "18:32:13.1527241","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\Programmable","SUCCESS","" "18:32:13.1531359","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\InprocServer32\ThreadingModel","SUCCESS","" "18:32:13.1533666","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\InprocServer32","SUCCESS","" "18:32:13.1540324","hpzwup01.exe","3936","RegDeleteValue","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\AppID","SUCCESS","" "18:32:13.1543609","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}\TypeLib","SUCCESS","" "18:32:13.1545933","hpzwup01.exe","3936","RegDeleteKey","HKCR\CLSID\{59B15028-399E-4B6D-A5F3-A8D7BFE17E1B}","SUCCESS","" "18:32:13.1647038","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{DE68F9EC-CBEC-416E-9719-6923F0128D76}\1.0\0\win32","SUCCESS","" "18:32:13.1650637","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{DE68F9EC-CBEC-416E-9719-6923F0128D76}\1.0\0","SUCCESS","" "18:32:13.1659372","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{DE68F9EC-CBEC-416E-9719-6923F0128D76}\1.0\FLAGS","SUCCESS","" "18:32:13.1663825","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{DE68F9EC-CBEC-416E-9719-6923F0128D76}\1.0\HELPDIR","SUCCESS","" "18:32:13.1666812","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{DE68F9EC-CBEC-416E-9719-6923F0128D76}\1.0","SUCCESS","" "18:32:13.1669720","hpzwup01.exe","3936","RegDeleteKey","HKCR\TypeLib\{DE68F9EC-CBEC-416E-9719-6923F0128D76}","SUCCESS","" "18:32:13.1677478","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{9BE2066D-5E51-4C15-B358-9EE4FEC47DDA}\ProxyStubClsid","SUCCESS","" "18:32:13.1704339","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{9BE2066D-5E51-4C15-B358-9EE4FEC47DDA}\ProxyStubClsid32","SUCCESS","" "18:32:13.1709295","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{9BE2066D-5E51-4C15-B358-9EE4FEC47DDA}\TypeLib","SUCCESS","" "18:32:13.1712298","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{9BE2066D-5E51-4C15-B358-9EE4FEC47DDA}","SUCCESS","" "18:32:13.1718989","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{23928D35-2D73-4276-97E8-A4835FE231E4}\ProxyStubClsid","SUCCESS","" "18:32:13.1725121","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{23928D35-2D73-4276-97E8-A4835FE231E4}\ProxyStubClsid32","SUCCESS","" "18:32:13.1729571","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{23928D35-2D73-4276-97E8-A4835FE231E4}\TypeLib","SUCCESS","" "18:32:13.1732686","hpzwup01.exe","3936","RegDeleteKey","HKCR\Interface\{23928D35-2D73-4276-97E8-A4835FE231E4}","SUCCESS","" "18:32:13.1802807","hpzwup01.exe","3936","RegDeleteKey","HKCR\AppID\{12B34448-B1B9-48D7-A98B-142AAD6C651F}","SUCCESS","" "18:32:13.1807173","hpzwup01.exe","3936","RegDeleteValue","HKCR\AppID\HPeSupport.DLL\AppID","SUCCESS","" "18:32:13.1809389","hpzwup01.exe","3936","RegDeleteKey","HKCR\AppID\HPeSupport.DLL","SUCCESS","" "18:33:11.1542290","hpzrcv01.exe","2980","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:33:11.1543084","hpzrcv01.exe","2980","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:33:11.1553295","hpzrcv01.exe","2980","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:33:11.1553918","hpzrcv01.exe","2980","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:33:27.0391057","hpzshl01.exe","3040","RegCreateKey","HKLM\SOFTWARE","SUCCESS","Desired Access: Read Control" "18:33:27.3339605","hpzshl01.exe","3040","RegCreateKey","HKLM\SOFTWARE\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}_Shl_Test","SUCCESS","Desired Access: Read Control" "18:33:27.3927607","hpzshl01.exe","3040","RegDeleteKey","HKLM\SOFTWARE\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}_Shl_Test","SUCCESS","" "18:33:27.3990258","hpzshl01.exe","3040","RegCreateKey","HKLM\SYSTEM","SUCCESS","Desired Access: Read Control" "18:33:27.4329985","hpzshl01.exe","3040","RegCreateKey","HKLM\SYSTEM\CurrentControlSet\Enum","SUCCESS","Desired Access: Read Control" "18:33:33.7613023","hpzshl01.exe","3040","RegCreateKey","HKLM\SOFTWARE\ICE","SUCCESS","Desired Access: Read Control" "18:33:33.7806690","hpzshl01.exe","3040","RegDeleteKey","HKLM\SOFTWARE\ICE","SUCCESS","" "18:33:33.7834819","hpzshl01.exe","3040","RegCreateKey","HKCR","SUCCESS","Desired Access: Read Control" "18:33:33.8019284","hpzshl01.exe","3040","RegCreateKey","HKCR\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}_Shl_Test","SUCCESS","Desired Access: Read Control" "18:33:33.8213524","hpzshl01.exe","3040","RegDeleteKey","HKCR\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}_Shl_Test","SUCCESS","" "18:33:33.8275780","hpzshl01.exe","3040","RegCreateKey","HKLM\SOFTWARE\HP","SUCCESS","Desired Access: Read Control" "18:33:34.0610409","hpzshl01.exe","3040","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard","SUCCESS","Desired Access: Read Control" "18:33:34.2317258","hpzshl01.exe","3040","RegCreateKey","HKLM\SOFTWARE\Hewlett Packard","SUCCESS","Desired Access: Read Control" "18:33:34.2932805","hpzshl01.exe","3040","RegDeleteKey","HKLM\SOFTWARE\Hewlett Packard","SUCCESS","" "18:33:34.3045710","hpzshl01.exe","3040","RegCreateKey","HKLM\SOFTWARE\LEAD Technologies, Inc.","SUCCESS","Desired Access: Read Control" "18:33:34.3233240","hpzshl01.exe","3040","RegDeleteKey","HKLM\SOFTWARE\LEAD Technologies, Inc.","SUCCESS","" "18:33:42.0393773","hpzprl01.exe","3476","RegCreateKey","HKLM\Software\Hewlett-Packard\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}-Setup-hpzprl01.dat","SUCCESS","Desired Access: Maximum Allowed" "18:33:42.0409722","hpzprl01.exe","3476","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}-Setup-hpzprl01.dat\Version","SUCCESS","Type: REG_SZ, Length: 18, Data: 6.0.0.71" "18:33:42.0422330","hpzprl01.exe","3476","RegCreateKey","HKLM\Software\Hewlett-Packard\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}-Setup-hpzprl01.dat","SUCCESS","Desired Access: Maximum Allowed" "18:33:42.0422791","hpzprl01.exe","3476","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}-Setup-hpzprl01.dat\Name","SUCCESS","Type: REG_SZ, Length: 78, Data: Uninstaller for Deskjet Printer Series" "18:33:49.7295225","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Hewlett-Packard\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}-hp-NPI-hpfprl01.dat","SUCCESS","Desired Access: Maximum Allowed" "18:33:49.7295804","hpzprl01.exe","3564","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}-hp-NPI-hpfprl01.dat\Version","SUCCESS","Type: REG_SZ, Length: 22, Data: 50.0.182.0" "18:33:49.7297251","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Hewlett-Packard\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}-hp-NPI-hpfprl01.dat","SUCCESS","Desired Access: Maximum Allowed" "18:33:49.7297625","hpzprl01.exe","3564","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}-hp-NPI-hpfprl01.dat\Name","SUCCESS","Type: REG_SZ, Length: 68, Data: installer for %DriverStackSeries%" "18:34:06.9597912","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:07.0323194","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\root","SUCCESS","Desired Access: All Access" "18:34:07.0325097","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\root","SUCCESS","Desired Access: All Access" "18:34:07.0327544","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.0328636","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.0329723","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.0335969","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\root","SUCCESS","Desired Access: All Access" "18:34:07.0336847","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\root","SUCCESS","Desired Access: All Access" "18:34:07.0337447","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.0350239","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.0427154","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.0428587","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Desired Access: All Access" "18:34:07.0429303","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.0665995","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.0667151","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.0668679","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\root","SUCCESS","Desired Access: All Access" "18:34:07.0669029","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\root\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.0670076","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\root\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.0671118","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\root\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.0673065","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\root","SUCCESS","Desired Access: All Access" "18:34:07.0673705","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\root","SUCCESS","Desired Access: All Access" "18:34:07.0674325","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.0675717","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.0676828","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.0680404","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\ca","SUCCESS","Desired Access: All Access" "18:34:07.0681782","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\ca","SUCCESS","Desired Access: All Access" "18:34:07.0682634","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.0683637","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.0684600","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.0687207","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\ca","SUCCESS","Desired Access: All Access" "18:34:07.0687701","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\ca\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.0688891","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\ca\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.0689947","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\ca\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.0691646","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\ca","SUCCESS","Desired Access: All Access" "18:34:07.0692272","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\ca","SUCCESS","Desired Access: All Access" "18:34:07.0692847","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.0722736","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.0725572","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.0727081","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\ca","SUCCESS","Desired Access: All Access" "18:34:07.0727447","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\ca\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.0728438","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\ca\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.0729464","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\ca\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.0731042","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\ca","SUCCESS","Desired Access: All Access" "18:34:07.0731651","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\ca","SUCCESS","Desired Access: All Access" "18:34:07.0732263","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.0734433","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.0735439","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.0738683","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\disallowed","SUCCESS","Desired Access: All Access" "18:34:07.0741362","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\disallowed","SUCCESS","Desired Access: All Access" "18:34:07.0742247","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.0743535","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.0744817","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.0747103","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed","SUCCESS","Desired Access: All Access" "18:34:07.0747511","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.0748681","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.0750078","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.0751830","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\disallowed","SUCCESS","Desired Access: All Access" "18:34:07.0856723","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\disallowed","SUCCESS","Desired Access: All Access" "18:34:07.0857505","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.0868157","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.0869188","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.0871051","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\disallowed","SUCCESS","Desired Access: All Access" "18:34:07.0871468","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.0872462","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.0873429","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.0875032","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\disallowed","SUCCESS","Desired Access: All Access" "18:34:07.0875636","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\disallowed","SUCCESS","Desired Access: All Access" "18:34:07.0876217","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.0877214","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.0878212","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.0880078","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.0881458","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.0882360","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.1190690","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed","SUCCESS","Desired Access: All Access" "18:34:07.1191112","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.1192620","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.1193824","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.1195889","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.1201378","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.1202339","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.1203996","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\disallowed","SUCCESS","Desired Access: All Access" "18:34:07.1204328","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.1205320","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.1206326","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.1207787","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.1208734","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.1209667","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.1212986","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: All Access" "18:34:07.1214366","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: All Access" "18:34:07.1215243","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.1216299","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.1217366","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.1219836","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: All Access" "18:34:07.1220230","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.1294223","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.1295700","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.1297776","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: All Access" "18:34:07.1298447","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: All Access" "18:34:07.1299670","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.1300726","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.1301746","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.1303576","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: All Access" "18:34:07.1304034","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.1305271","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.1306369","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.1308115","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\trust","SUCCESS","Desired Access: All Access" "18:34:07.1308777","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\trust","SUCCESS","Desired Access: All Access" "18:34:07.1309356","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.1310378","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.1311384","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.1315253","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\my","SUCCESS","Desired Access: All Access" "18:34:07.1462509","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon","SUCCESS","Desired Access: Read/Write" "18:34:07.1906345","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.1907893","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.1908968","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.1912807","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.1923585","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.1924537","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.1926292","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.2180363","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.2181752","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.2195128","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\root","SUCCESS","Desired Access: All Access" "18:34:07.2195488","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\root\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.2196499","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\root\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.2197438","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\root\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.2199284","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.2200287","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.2204542","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.2217840","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.2219027","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.2220033","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.2221609","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: All Access" "18:34:07.2221944","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.2223081","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.2224036","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.2225637","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.2226570","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.2227880","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.2228869","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: All Access" "18:34:07.2229213","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.2230227","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.2231208","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.2232691","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.2233644","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.2234546","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.2235680","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.2236630","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.2237571","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.2240186","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\ca","SUCCESS","Desired Access: All Access" "18:34:07.2240519","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\ca\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.2241645","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\ca\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.2242656","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\ca\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.2244184","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.2407604","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.2410163","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.2412616","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\ca","SUCCESS","Desired Access: All Access" "18:34:07.2412968","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\ca\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.2413974","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\ca\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.2414896","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\ca\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.2416664","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.2417678","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.2418639","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.2703550","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:07.2706413","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:07.2707296","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.2708802","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.2709771","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.2712095","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:07.2712554","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.2713855","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.2715037","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.2716892","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:07.2718973","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:07.2730031","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.2735780","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.2736755","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.2738116","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:07.2738454","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.2739423","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.2740350","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.2741848","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:07.2742490","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:07.2743784","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.2744745","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.2745706","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.2747446","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.2750553","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.2751536","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.2753076","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:07.2753430","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.2755065","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.2756531","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.2758367","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.2762708","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.2763636","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.2764806","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:07.2765122","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.2767320","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.2768242","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:07.2769728","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:07.2770712","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:07.2771659","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.1715994","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:08.2094715","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.2097730","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.2098685","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.2099931","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.2100892","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.2103228","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.2103613","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.2104778","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.2106641","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.2108488","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.2110603","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.2111178","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.2116014","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.2117375","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.2118710","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.2119031","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.2119984","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.2120911","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.2122389","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.2123018","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.2123613","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.2124563","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.2125524","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.2127267","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.2128789","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.2129728","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.2131209","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.2131586","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.2132840","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.2134081","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.2136377","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.2141529","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.2142526","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.2144378","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.2144691","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.2145618","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.2146540","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.2147987","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.2149055","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.2150016","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.3714840","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.3717796","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.3718707","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.3719866","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.3720824","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.3724844","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.3725582","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.3726761","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.3727875","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.3729591","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.3731669","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.3732247","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.3737860","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.3738874","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.3740207","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.3740531","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.3741492","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.3742425","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.3743925","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.3744553","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.3745146","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.3746098","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.3747068","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.3749110","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.3750213","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.3751152","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.3752649","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.3752993","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.3754169","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.3755345","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.3757214","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.3764729","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.3765707","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.3766889","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.3767199","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.3768182","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.3769110","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.3770588","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.3772535","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.3773515","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.7248588","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:08.7587064","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.7590073","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.7590989","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.7592157","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.7593504","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.7596521","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.7596906","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.7599261","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.7601248","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.7602913","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.7606240","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.7606880","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.7611461","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.7612436","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.7613760","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.7614096","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.7615034","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.7616255","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.7617755","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.7618384","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.7618965","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.7619926","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.7620884","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.7622569","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.7623650","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.7624586","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.7626075","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.7626424","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.7653355","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.7654911","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.7657084","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.7662241","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.7663230","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.7664418","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.7664739","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.7665722","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.7666650","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.7668119","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.7669119","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.7670083","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.7870008","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.7873047","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.7873961","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.7875185","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.7876120","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.7878783","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.7879174","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.7880398","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.7881565","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.7883303","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.7885686","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.7886303","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.7891131","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.7892114","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.7893422","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.7893746","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.7894682","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.7895603","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.7897073","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.7897699","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.7898294","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.7899255","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.7900213","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.7902671","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.7903764","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.7904697","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.7906200","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.7906541","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.7907686","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.7908803","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.7910650","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.7924900","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.7925906","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.7927119","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:08.7927440","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.7928379","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.7929295","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:08.7930815","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:08.7931784","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:08.7932728","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.0041192","hpzprl01.exe","3564","RegCreateKey","HKLM\System\LastKnownGoodRecovery\LastGood","SUCCESS","Desired Access: All Access" "18:34:09.0064234","hpzprl01.exe","3564","RegSetValue","HKLM\SYSTEM\LastKnownGoodRecovery\LastGood\INF/oem16.inf","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "18:34:09.0182056","hpzprl01.exe","3564","RegCreateKey","HKLM\System\LastKnownGoodRecovery\LastGood","SUCCESS","Desired Access: All Access" "18:34:09.0182746","hpzprl01.exe","3564","RegSetValue","HKLM\SYSTEM\LastKnownGoodRecovery\LastGood\INF/oem16.PNF","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "18:34:09.0226293","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:09.0872937","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.0875809","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.0876672","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.0877812","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.0878773","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.0881514","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.0881908","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.0884402","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.0885606","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.0887274","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.0889350","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.0889956","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.0895043","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.0896024","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.0897354","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.0897681","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.0898633","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.0899563","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.0901041","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.0901670","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.0902254","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.0903609","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.0904595","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.0906257","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.0907397","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.0908330","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.1142153","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.1143296","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.1144810","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.1146061","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.1148059","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.1163820","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.1164804","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.1166519","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.1166860","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.1167815","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.1168732","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.1170316","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.1171319","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.1172271","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.1185091","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:09.1305174","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.1308157","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.1309141","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.1310526","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.1311479","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.1314722","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.1315111","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.1316259","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.1317374","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.1319025","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.1332507","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.1333188","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.1339672","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.1341156","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.1342494","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.1342818","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.1343760","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.1344684","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.1346159","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.1346782","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.1347369","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.1348724","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.1349690","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.1351353","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.1352411","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.1353345","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.1354864","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.1355211","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.1356337","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.1357454","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.1359650","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.1363991","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.1364961","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.1366117","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.1366427","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.1367377","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.1368299","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.1369740","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.1371107","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.1372101","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.3932896","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:09.4444349","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.4447780","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.4448724","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.4450012","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.4450970","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.4453317","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.4453725","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.4454973","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.4456091","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.4459077","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.4504605","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.4505206","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.4510103","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.4511087","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.4512841","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.4513174","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.4514129","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.4515056","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.4516548","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.4517174","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.4517772","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.4522376","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.4524482","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.4526245","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.4527424","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.4528354","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.4529860","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.4530223","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.4531424","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.4532774","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.4535559","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.4539973","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.4540948","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.4542099","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.4542412","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.4543359","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.4544270","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.4545971","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.4547407","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.4548388","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.5799340","hpzprl01.exe","3564","RegCreateKey","HKLM\System\LastKnownGoodRecovery\LastGood","SUCCESS","Desired Access: All Access" "18:34:09.5800044","hpzprl01.exe","3564","RegSetValue","HKLM\SYSTEM\LastKnownGoodRecovery\LastGood\INF/oem17.inf","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "18:34:09.5891597","hpzprl01.exe","3564","RegCreateKey","HKLM\System\LastKnownGoodRecovery\LastGood","SUCCESS","Desired Access: All Access" "18:34:09.5892240","hpzprl01.exe","3564","RegSetValue","HKLM\SYSTEM\LastKnownGoodRecovery\LastGood\INF/oem17.PNF","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "18:34:09.6226746","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:09.6493984","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.6497001","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.6497906","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.6504320","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.6505332","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.6507813","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.6508170","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.6509357","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.6513288","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.6515917","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.6518051","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.6518630","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.6523932","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.6524896","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.6526214","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.6526527","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.6527466","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.6528377","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.6529832","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.6530452","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.6531028","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.6531961","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.6533296","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.6557872","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.6559288","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.6560247","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.6561817","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.6562213","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.6563451","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.6564756","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.6567192","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.6572103","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.6583607","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.6584962","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.6585306","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.6586253","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.6587177","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.6588711","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.6590270","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.6591245","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.6604562","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:09.6720063","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.6723016","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.6723901","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.6725047","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.6726011","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.6729332","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.6729693","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.6730813","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.6731930","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.6733570","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.6735660","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.6736241","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.6776836","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.6778104","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.6779621","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.6779970","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.6780931","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.6781864","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.6783825","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.6784499","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.6785122","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.6786105","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.6796640","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.6798542","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.6799688","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.6800637","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.6802213","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.6802573","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.6803758","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.6804909","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.6807728","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.6820771","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.6821883","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.6823112","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:09.6823450","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.6824411","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.6825319","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.6826884","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:09.6827884","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:09.6829697","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:09.9911010","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:10.0071947","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.0074950","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.0075853","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.0077171","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.0078129","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.0081621","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.0081987","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.0083138","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.0084261","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.0085926","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.0088055","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.0088673","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.0093659","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.0094645","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.0095972","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.0096297","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.0097252","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.0098179","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.0099660","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.0100280","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.0100873","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.0101839","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.0103197","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.0104884","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.0105971","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.0106904","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.0108393","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.0108737","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.0109876","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.0111008","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.0112857","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.0117626","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.0118643","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.0119800","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.0120112","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.0121065","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.0122001","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.0123440","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.0124420","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.0157899","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.1293907","hpzprl01.exe","3564","RegCreateKey","HKLM\System\LastKnownGoodRecovery\LastGood","SUCCESS","Desired Access: All Access" "18:34:10.1294644","hpzprl01.exe","3564","RegSetValue","HKLM\SYSTEM\LastKnownGoodRecovery\LastGood\INF/oem18.inf","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "18:34:10.1707546","hpzprl01.exe","3564","RegCreateKey","HKLM\System\LastKnownGoodRecovery\LastGood","SUCCESS","Desired Access: All Access" "18:34:10.1708233","hpzprl01.exe","3564","RegSetValue","HKLM\SYSTEM\LastKnownGoodRecovery\LastGood\INF/oem18.PNF","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "18:34:10.1857775","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:10.2622210","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.2625224","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.2626138","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.2627822","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.2630448","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.2632856","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.2633228","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.2634390","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.2635577","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.2637240","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.2639734","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.2640360","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.2644844","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.2645833","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.2647143","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.2647470","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.2648425","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.2649356","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.2651621","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.2652292","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.2652890","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.2653870","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.2654840","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.2656482","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.2657563","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.2658496","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.2659997","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.2660337","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.2661882","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.2663025","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.2664877","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.2669205","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.2670174","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.2671317","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.2671624","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.2672942","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.2673889","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.2675348","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.2676351","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.2677348","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.2705667","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:10.2814379","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.2817335","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.2818215","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.2819402","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.2820372","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.2823107","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.2823462","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.2824660","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.2825805","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.2827465","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.2829580","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.2830169","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.2835050","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.2836022","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.2837324","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.2837642","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.2838586","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.2839506","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.2840981","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.2841595","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.2842185","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.2843162","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.2844531","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.2846171","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.2847289","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.2848213","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.2849666","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.2849998","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.2851203","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.2852381","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.2854267","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.2860729","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.2861659","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.2862824","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.2863137","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.2864053","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.2865224","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.2867059","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.2868059","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.2869006","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.4037714","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:10.4169898","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.4173390","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.4174304","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.4175469","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.4176446","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.4178779","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.4179179","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.4180383","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.4181514","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.4183844","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.4185995","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.4186604","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.4194097","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.4196200","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.4197561","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.4197890","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.4198832","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.4199751","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.4201218","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.4201846","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.4202436","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.4203397","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.4204347","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.4206338","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.4207861","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.4208797","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.4210319","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.4210680","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.4211856","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.4212985","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.4214831","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.4219670","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.4220645","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.4221810","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.4222117","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.4223072","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.4223992","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.4225436","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.4226444","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.4227411","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.9088520","hpzprl01.exe","3564","RegCreateKey","HKLM\System\LastKnownGoodRecovery\LastGood","SUCCESS","Desired Access: All Access" "18:34:10.9089300","hpzprl01.exe","3564","RegSetValue","HKLM\SYSTEM\LastKnownGoodRecovery\LastGood\INF/oem19.inf","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "18:34:10.9197057","hpzprl01.exe","3564","RegCreateKey","HKLM\System\LastKnownGoodRecovery\LastGood","SUCCESS","Desired Access: All Access" "18:34:10.9198154","hpzprl01.exe","3564","RegSetValue","HKLM\SYSTEM\LastKnownGoodRecovery\LastGood\INF/oem19.PNF","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "18:34:10.9230200","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:10.9447672","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.9451030","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.9451944","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.9453162","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.9454165","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.9456598","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.9456972","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.9458134","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.9459269","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.9461858","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.9464029","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.9464641","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.9469113","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.9470091","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.9473798","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.9474139","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.9475111","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.9476022","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.9477528","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.9478157","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.9478754","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.9479713","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.9480679","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.9482327","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.9483710","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.9484641","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.9486121","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.9486479","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.9487644","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.9488811","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.9490692","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.9495555","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.9496530","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.9497676","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.9497983","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.9498941","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.9499855","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.9501305","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.9502308","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.9512932","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.9537100","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:10.9647245","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.9650237","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.9651151","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.9652324","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.9653263","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.9656433","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.9656833","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.9658017","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.9672617","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.9674732","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.9677553","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.9678137","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.9682937","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.9683912","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.9685222","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.9685540","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.9686485","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.9687401","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.9689834","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.9690496","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.9691083","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.9692027","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.9692983","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.9694575","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.9695634","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.9696573","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.9698059","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.9698394","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.9699900","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.9701037","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.9702867","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.9707197","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.9708124","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.9709295","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:10.9709611","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.9710535","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.9711742","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:10.9713209","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:10.9714187","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:10.9715153","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.0372360","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:11.0501085","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.0504066","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.0504971","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.0506181","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.0507125","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.0510486","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.0510886","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.0512115","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.0513296","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.0515073","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.0517157","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.0517730","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.0522865","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.0523840","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.0525144","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.0525480","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.0526424","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.0527337","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.0528804","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.0529424","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.0530022","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.0530961","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.0531919","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.0534271","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.0535517","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.0536445","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.0537906","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.0538286","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.0539562","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.0540702","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.0542764","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.0547661","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.0549016","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.0550181","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.0550488","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.0551405","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.0552321","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.0553760","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.0554735","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.0556073","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.2381084","hpzprl01.exe","3564","RegCreateKey","HKLM\System\LastKnownGoodRecovery\LastGood","SUCCESS","Desired Access: All Access" "18:34:11.2381771","hpzprl01.exe","3564","RegSetValue","HKLM\SYSTEM\LastKnownGoodRecovery\LastGood\INF/oem20.inf","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "18:34:11.2583696","hpzprl01.exe","3564","RegCreateKey","HKLM\System\LastKnownGoodRecovery\LastGood","SUCCESS","Desired Access: All Access" "18:34:11.2584317","hpzprl01.exe","3564","RegSetValue","HKLM\SYSTEM\LastKnownGoodRecovery\LastGood\INF/oem20.PNF","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "18:34:11.2667668","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:11.2943351","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.2947357","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.2948276","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.2949494","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.2950497","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.2952894","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.2953266","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.2954428","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.2956012","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.2957722","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.2959873","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.2960490","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.2965295","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.2966628","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.2968005","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.2968326","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.2969282","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.2970212","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.2971721","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.2972349","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.2972939","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.2973916","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.2974889","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.2976545","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.2978043","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.2979543","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.2981091","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.2981498","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.2982831","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.2984046","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.2985971","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.2991050","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.2992022","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.2993170","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.2993480","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.2994447","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.2995369","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.2996813","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.2997813","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.2998783","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.3028778","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:11.3137119","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.3140477","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.3141365","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.3142572","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.3143550","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.3145871","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.3146229","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.3147385","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.3148495","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.3150548","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.3153797","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.3154384","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.3159066","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.3160035","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.3161764","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.3162091","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.3163038","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.3163955","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.3165435","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.3166058","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.3166642","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.3167614","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.3168570","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.3170173","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.3171218","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.3173964","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.3175456","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.3175797","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.3176925","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.3178040","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.3179859","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.3184628","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.3185561","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.3186714","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.3187019","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.3187944","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.3188860","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.3190304","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.3191282","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.3192240","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.4566873","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:11.4718155","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.4721155","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.4722122","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.4725281","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.4726273","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.4728631","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.4729011","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.4730182","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.4731469","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.4733280","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.4735682","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.4736277","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.4741289","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.4742270","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.4743588","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.4743926","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.4744876","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.4745790","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.4747678","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.4748310","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.4748899","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.4749843","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.4750799","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.4752450","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.4753503","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.4754428","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.4755897","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.4756230","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.4757364","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.4758844","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.4760741","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.4765038","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.4765954","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.4767111","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.4767421","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.4768334","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.4769653","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.4771600","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.4772598","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.4773559","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.7117689","hpzprl01.exe","3564","RegCreateKey","HKLM\System\LastKnownGoodRecovery\LastGood","SUCCESS","Desired Access: All Access" "18:34:11.7118516","hpzprl01.exe","3564","RegSetValue","HKLM\SYSTEM\LastKnownGoodRecovery\LastGood\INF/oem21.inf","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "18:34:11.7389553","hpzprl01.exe","3564","RegCreateKey","HKLM\System\LastKnownGoodRecovery\LastGood","SUCCESS","Desired Access: All Access" "18:34:11.7390358","hpzprl01.exe","3564","RegSetValue","HKLM\SYSTEM\LastKnownGoodRecovery\LastGood\INF/oem21.PNF","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "18:34:11.7435573","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:11.7866332","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.7869245","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.7870184","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.7871472","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.7872807","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.7875196","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.7875590","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.7876794","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.7878213","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.7880054","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.7882225","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.7882808","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.7888698","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.7889723","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.7891058","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.7891382","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.7892338","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.7893262","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.7894749","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.7895768","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.7896383","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.7897352","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.7898316","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.7899989","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.7901037","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.7901967","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.7903445","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.7903775","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.7904915","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.7906021","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.7908253","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.7912561","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.7913486","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.7914639","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.7914949","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.7915874","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.7916799","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.7918604","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.7919615","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.7920579","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.7954234","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:11.8061946","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.8064832","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.8065720","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.8068905","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.8070000","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.8072335","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.8072696","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.8074255","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.8075369","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.8076995","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.8079962","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.8080546","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.8085116","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.8086075","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.8087374","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.8087692","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.8088628","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.8089916","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.8091410","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.8092031","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.8092606","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.8093573","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.8094517","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.8096126","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.8113176","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.8114804","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.8116550","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.8116928","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.8118132","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.8119277","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.8121166","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.8126191","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.8127152","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.8128320","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.8128639","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.8129572","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.8130480","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.8131913","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.8132882","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.8133826","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.9029429","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:11.9172025","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.9175423","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.9176330","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.9177571","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.9178537","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.9180909","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.9181270","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.9182384","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.9183474","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.9185524","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.9187622","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.9188198","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.9194271","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.9195266","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.9198208","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.9198540","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.9199501","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.9200420","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.9201895","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.9202518","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.9203113","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.9204052","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.9205007","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.9206633","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.9208038","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.9209002","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.9222269","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.9222627","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.9223820","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.9224954","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.9226851","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.9232005","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.9233930","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.9235120","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:11.9235441","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.9236397","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.9237324","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:11.9238802","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:11.9239788","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:11.9240755","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.0174181","hpzprl01.exe","3564","RegCreateKey","HKLM\System\LastKnownGoodRecovery\LastGood","SUCCESS","Desired Access: All Access" "18:34:12.0174868","hpzprl01.exe","3564","RegSetValue","HKLM\SYSTEM\LastKnownGoodRecovery\LastGood\INF/oem22.inf","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "18:34:12.0269944","hpzprl01.exe","3564","RegCreateKey","HKLM\System\LastKnownGoodRecovery\LastGood","SUCCESS","Desired Access: All Access" "18:34:12.0270676","hpzprl01.exe","3564","RegSetValue","HKLM\SYSTEM\LastKnownGoodRecovery\LastGood\INF/oem22.PNF","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "18:34:12.0332684","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:12.0433635","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.0453537","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.0454683","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.0455862","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.0456826","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.0459334","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.0459734","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.0460874","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.0461985","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.0464070","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.0466218","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.0466838","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.0471503","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.0472490","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.0473819","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.0474507","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.0475948","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.0476901","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.0478401","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.0479030","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.0479627","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.0480608","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.0481572","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.0483234","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.0484315","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.0485257","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.0487156","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.0487505","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.0488659","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.0489788","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.0491626","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.0505455","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.0506536","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.0507734","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.0508053","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.0509352","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.0510899","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.0512472","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.0513467","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.0514419","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.0532106","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:12.0639882","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.0642846","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.0643763","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.0644992","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.0646361","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.0648741","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.0649115","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.0650272","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.0651440","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.0653105","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.0655220","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.0655837","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.0664763","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.0665760","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.0667129","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.0667461","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.0668777","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.0669721","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.0671224","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.0671853","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.0672445","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.0674040","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.0675010","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.0676658","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.0677784","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.0678711","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.0680544","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.0680893","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.0682650","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.0683818","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.0685679","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.0690101","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.0691378","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.0692534","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.0692842","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.0693791","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.0694705","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.0696144","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.0697127","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.0698088","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.1605337","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:34:12.1731904","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.1734862","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.1735776","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.1736944","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.1737905","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.1740260","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.1741707","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.1742900","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.1743986","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.1745671","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.1747749","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.1748328","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.1754178","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.1755164","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.1756491","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.1756829","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.1757787","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.1758701","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.1760167","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.1760815","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.1761405","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.1762357","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.1763598","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.1765861","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.1766945","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.1767872","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.1769344","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.1769674","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.1770828","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.1771945","hpzprl01.exe","3564","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.1773792","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.1778591","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.1779522","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.1780675","hpzprl01.exe","3564","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:34:12.1780986","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.1781905","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.1782821","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.1784254","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:34:12.1785226","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:34:12.1786536","hpzprl01.exe","3564","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:34:12.2459929","hpzprl01.exe","3564","RegCreateKey","HKLM\System\LastKnownGoodRecovery\LastGood","SUCCESS","Desired Access: All Access" "18:34:12.2460631","hpzprl01.exe","3564","RegSetValue","HKLM\SYSTEM\LastKnownGoodRecovery\LastGood\INF/oem23.inf","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "18:34:12.2563996","hpzprl01.exe","3564","RegCreateKey","HKLM\System\LastKnownGoodRecovery\LastGood","SUCCESS","Desired Access: All Access" "18:34:12.2564756","hpzprl01.exe","3564","RegSetValue","HKLM\SYSTEM\LastKnownGoodRecovery\LastGood\INF/oem23.PNF","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "18:34:39.5398965","hpzarp01.exe","2172","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}","SUCCESS","Desired Access: All Access" "18:34:39.5409989","hpzarp01.exe","2172","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}\UninstallString","SUCCESS","Type: REG_SZ, Length: 232, Data: C:\Program Files\HP\Digital Imaging\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}\setup\hpzscr01.exe -datfile hpfscr09.dat" "18:34:39.5488513","hpzarp01.exe","2172","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}\DisplayName","SUCCESS","Type: REG_SZ, Length: 46, Data: HP Deskjet 6900 series" "18:34:39.5559524","hpzarp01.exe","2172","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}\DisplayIcon","SUCCESS","Type: REG_SZ, Length: 192, Data: C:\Program Files\HP\Digital Imaging\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}\setup\hpzscr01.exe,0" "18:34:39.5563712","hpzarp01.exe","2172","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}\DisplayVersion","SUCCESS","Type: REG_SZ, Length: 8, Data: 6.0" "18:34:39.5570372","hpzarp01.exe","2172","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}\Publisher","SUCCESS","Type: REG_SZ, Length: 6, Data: HP" "18:34:39.5573713","hpzarp01.exe","2172","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}\URLUpdateInfo","SUCCESS","Type: REG_SZ, Length: 52, Data: http://www.hp.com/support" "18:34:39.5586863","hpzarp01.exe","2172","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}\HelpLink","SUCCESS","Type: REG_SZ, Length: 52, Data: http://www.hp.com/support" "18:35:13.5759377","hpzdui01.exe","2740","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\EnableBalloonTips","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "18:36:47.6025075","hpzdui01.exe","2740","RegDeleteValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\EnableBalloonTips","SUCCESS","" "18:37:30.5002616","hpzmsi01.exe","2256","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{688F7E20-2234-4ab3-94B2-38BF116B0575}","SUCCESS","Desired Access: All Access" "18:37:30.5015103","hpzmsi01.exe","2256","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{688F7E20-2234-4ab3-94B2-38BF116B0575}\CDGuid","SUCCESS","Type: REG_SZ, Length: 78, Data: {7ADE9F27-A175-447F-A4B4-B05FA82735E1}" "18:37:30.5042570","hpzmsi01.exe","2256","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{688F7E20-2234-4ab3-94B2-38BF116B0575}","SUCCESS","Desired Access: All Access" "18:37:30.5043065","hpzmsi01.exe","2256","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{688F7E20-2234-4ab3-94B2-38BF116B0575}\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1006633156" "18:37:30.5053893","hpzmsi01.exe","2256","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{688F7E20-2234-4ab3-94B2-38BF116B0575}\Version_STR","SUCCESS","Type: REG_SZ, Length: 14, Data: 60.0.1" "18:37:30.5058293","hpzmsi01.exe","2256","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{688F7E20-2234-4ab3-94B2-38BF116B0575}\Filename","SUCCESS","Type: REG_SZ, Length: 54, Data: D:\setup\Readme\Readme.msi" "18:37:30.5061995","hpzmsi01.exe","2256","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{688F7E20-2234-4ab3-94B2-38BF116B0575}\section","SUCCESS","Type: REG_SZ, Length: 22, Data: MSI.Readme" "18:37:49.3731099","hpzmsi01.exe","2256","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{86ABAF46-1F4E-4b45-9E13-6246D83303F3}","SUCCESS","Desired Access: All Access" "18:37:49.3767855","hpzmsi01.exe","2256","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{86ABAF46-1F4E-4b45-9E13-6246D83303F3}\CDGuid","SUCCESS","Type: REG_SZ, Length: 78, Data: {7ADE9F27-A175-447F-A4B4-B05FA82735E1}" "18:37:49.3789618","hpzmsi01.exe","2256","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{86ABAF46-1F4E-4b45-9E13-6246D83303F3}","SUCCESS","Desired Access: All Access" "18:37:49.3790529","hpzmsi01.exe","2256","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{86ABAF46-1F4E-4b45-9E13-6246D83303F3}\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1006633156" "18:37:49.3792979","hpzmsi01.exe","2256","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{86ABAF46-1F4E-4b45-9E13-6246D83303F3}\Version_STR","SUCCESS","Type: REG_SZ, Length: 14, Data: 60.0.1" "18:37:49.3795269","hpzmsi01.exe","2256","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{86ABAF46-1F4E-4b45-9E13-6246D83303F3}\Filename","SUCCESS","Type: REG_SZ, Length: 72, Data: D:\setup\PSTAPlugin\DJ_TAPlugin.msi" "18:37:49.3799773","hpzmsi01.exe","2256","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{86ABAF46-1F4E-4b45-9E13-6246D83303F3}\section","SUCCESS","Type: REG_SZ, Length: 32, Data: MSI.DJ_TAPlugin" "18:37:51.5704951","hpzmsi01.exe","2788","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install","SUCCESS","Desired Access: All Access" "18:37:51.5724663","hpzmsi01.exe","2788","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{688F7E20-2234-4ab3-94B2-38BF116B0575}","SUCCESS","Desired Access: All Access" "18:37:51.5818798","hpzmsi01.exe","2788","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{688F7E20-2234-4ab3-94B2-38BF116B0575}","SUCCESS","Desired Access: All Access" "18:37:51.5837800","hpzmsi01.exe","2788","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{688F7E20-2234-4ab3-94B2-38BF116B0575}","SUCCESS","Desired Access: All Access" "18:37:51.5839336","hpzmsi01.exe","2788","RegDeleteValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{688F7E20-2234-4ab3-94B2-38BF116B0575}\CDGuid","SUCCESS","" "18:37:51.5861688","hpzmsi01.exe","2788","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{86ABAF46-1F4E-4b45-9E13-6246D83303F3}","SUCCESS","Desired Access: All Access" "18:37:51.6301367","hpzmsi01.exe","2788","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{86ABAF46-1F4E-4b45-9E13-6246D83303F3}","SUCCESS","Desired Access: All Access" "18:37:51.6321652","hpzmsi01.exe","2788","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{86ABAF46-1F4E-4b45-9E13-6246D83303F3}","SUCCESS","Desired Access: All Access" "18:37:51.6323130","hpzmsi01.exe","2788","RegDeleteValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{86ABAF46-1F4E-4b45-9E13-6246D83303F3}\CDGuid","SUCCESS","" "18:37:57.0811603","hpzrcv01.exe","3376","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:37:57.0812583","hpzrcv01.exe","3376","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:37:57.0874946","hpzrcv01.exe","3376","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:37:57.0876454","hpzrcv01.exe","3376","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:38:03.4180559","hpzcdl01.exe","1876","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}","SUCCESS","Desired Access: All Access" "18:38:03.4563820","hpzcdl01.exe","1876","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}\SourceDir","SUCCESS","Type: REG_SZ, Length: 8, Data: D:\" "18:38:26.4733517","hpzmsi01.exe","3824","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{831FF972-593D-46BB-918D-D4D1B9608E12}","SUCCESS","Desired Access: All Access" "18:38:26.4745971","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{831FF972-593D-46BB-918D-D4D1B9608E12}\CDGuid","SUCCESS","Type: REG_SZ, Length: 78, Data: {7ADE9F27-A175-447F-A4B4-B05FA82735E1}" "18:38:26.4766639","hpzmsi01.exe","3824","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{831FF972-593D-46BB-918D-D4D1B9608E12}","SUCCESS","Desired Access: All Access" "18:38:26.4767491","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{831FF972-593D-46BB-918D-D4D1B9608E12}\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 16777216" "18:38:26.4769589","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{831FF972-593D-46BB-918D-D4D1B9608E12}\Version_STR","SUCCESS","Type: REG_SZ, Length: 12, Data: 1.0.1" "18:38:26.4770899","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{831FF972-593D-46BB-918D-D4D1B9608E12}\Filename","SUCCESS","Type: REG_SZ, Length: 90, Data: D:\setup\QFolder\DeviceManagementQFolder.MSI" "18:38:26.4788597","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{831FF972-593D-46BB-918D-D4D1B9608E12}\section","SUCCESS","Type: REG_SZ, Length: 56, Data: MSI.DeviceManagementQfolder" "18:38:49.6480588","HpqUnApl.exe","1200","RegCreateKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\HPUnloadAutoplay","SUCCESS","Desired Access: All Access, WOW64_64Key" "18:38:49.6666841","HpqUnApl.exe","1200","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\HPUnloadAutoplay\Action","SUCCESS","Type: REG_SZ, Length: 32, Data: Transfer Images" "18:38:49.7245222","HpqUnApl.exe","1200","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\HPUnloadAutoplay\Provider","SUCCESS","Type: REG_SZ, Length: 64, Data: HP Photosmart Transfer Software" "18:38:49.7249454","HpqUnApl.exe","1200","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\HPUnloadAutoplay\DefaultIcon","SUCCESS","Type: REG_SZ, Length: 120, Data: ""C:\Program Files\HP\Digital Imaging\Unload\HpqUnApl.exe"",0" "18:38:49.7251762","HpqUnApl.exe","1200","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\HPUnloadAutoplay\InvokeProgID","SUCCESS","Type: REG_SZ, Length: 36, Data: HpqUnApl.Autoplay" "18:38:49.7256723","HpqUnApl.exe","1200","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\HPUnloadAutoplay\InvokeVerb","SUCCESS","Type: REG_SZ, Length: 10, Data: Play" "18:38:49.7261503","HpqUnApl.exe","1200","RegCreateKey","HKCR\HpqUnApl.Autoplay","SUCCESS","Desired Access: All Access, WOW64_64Key" "18:38:49.7265093","HpqUnApl.exe","1200","RegCreateKey","HKCR\HpqUnApl.Autoplay\Shell","SUCCESS","Desired Access: All Access, WOW64_64Key" "18:38:49.7268082","HpqUnApl.exe","1200","RegCreateKey","HKCR\HpqUnApl.Autoplay\Shell\Play","SUCCESS","Desired Access: All Access, WOW64_64Key" "18:38:49.7272284","HpqUnApl.exe","1200","RegCreateKey","HKCR\HpqUnApl.Autoplay\Shell\Play\DropTarget","SUCCESS","Desired Access: All Access, WOW64_64Key" "18:38:49.7274756","HpqUnApl.exe","1200","RegSetValue","HKCR\HpqUnApl.Autoplay\Shell\Play\DropTarget\CLSID","SUCCESS","Type: REG_SZ, Length: 78, Data: {E1A1C814-FD09-4c9d-BB4A-0394B836A1F0}" "18:38:49.7277354","HpqUnApl.exe","1200","RegCreateKey","HKCR\CLSID\{E1A1C814-FD09-4c9d-BB4A-0394B836A1F0}","SUCCESS","Desired Access: All Access, WOW64_64Key" "18:38:49.7281154","HpqUnApl.exe","1200","RegCreateKey","HKCR\CLSID\{E1A1C814-FD09-4c9d-BB4A-0394B836A1F0}\LocalServer32","SUCCESS","Desired Access: All Access, WOW64_64Key" "18:38:49.7285096","HpqUnApl.exe","1200","RegSetValue","HKCR\CLSID\{E1A1C814-FD09-4c9d-BB4A-0394B836A1F0}\LocalServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 112, Data: C:\Program Files\HP\Digital Imaging\Unload\HpqUnApl.exe" "18:38:51.0192647","hpzmsi01.exe","3824","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{B0564E46-594F-4E69-AEF9-AEE9C73050B8}","SUCCESS","Desired Access: All Access" "18:38:51.0202014","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{B0564E46-594F-4E69-AEF9-AEE9C73050B8}\CDGuid","SUCCESS","Type: REG_SZ, Length: 78, Data: {7ADE9F27-A175-447F-A4B4-B05FA82735E1}" "18:38:51.0244025","hpzmsi01.exe","3824","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{B0564E46-594F-4E69-AEF9-AEE9C73050B8}","SUCCESS","Desired Access: All Access" "18:38:51.0244698","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{B0564E46-594F-4E69-AEF9-AEE9C73050B8}\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 100663296" "18:38:51.0249255","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{B0564E46-594F-4E69-AEF9-AEE9C73050B8}\Version_STR","SUCCESS","Type: REG_SZ, Length: 12, Data: 6.0.1" "18:38:51.0250640","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{B0564E46-594F-4E69-AEF9-AEE9C73050B8}\Filename","SUCCESS","Type: REG_SZ, Length: 66, Data: D:\setup\UnloadIntent\Unload.msi" "18:38:51.0253068","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{B0564E46-594F-4E69-AEF9-AEE9C73050B8}\section","SUCCESS","Type: REG_SZ, Length: 22, Data: MSI.Unload" "18:39:18.0828563","hpzmsi01.exe","3824","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{9716D554-3FBD-4DFD-8AE0-424EFD722D74}","SUCCESS","Desired Access: All Access" "18:39:18.0884313","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{9716D554-3FBD-4DFD-8AE0-424EFD722D74}\CDGuid","SUCCESS","Type: REG_SZ, Length: 78, Data: {7ADE9F27-A175-447F-A4B4-B05FA82735E1}" "18:39:18.1165930","hpzmsi01.exe","3824","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{9716D554-3FBD-4DFD-8AE0-424EFD722D74}","SUCCESS","Desired Access: All Access" "18:39:18.1166695","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{9716D554-3FBD-4DFD-8AE0-424EFD722D74}\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1006633115" "18:39:18.1173405","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{9716D554-3FBD-4DFD-8AE0-424EFD722D74}\Version_STR","SUCCESS","Type: REG_SZ, Length: 14, Data: 60.0.1" "18:39:18.1175104","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{9716D554-3FBD-4DFD-8AE0-424EFD722D74}\Filename","SUCCESS","Type: REG_SZ, Length: 78, Data: D:\setup\Destinations\Destinations.msi" "18:39:18.1179680","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{9716D554-3FBD-4DFD-8AE0-424EFD722D74}\section","SUCCESS","Type: REG_SZ, Length: 34, Data: MSI.Destinations" "18:39:58.3551789","hpzmsi01.exe","3824","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{348082C7-A032-4e1d-9B2A-41514C010335}","SUCCESS","Desired Access: All Access" "18:39:58.3588774","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{348082C7-A032-4e1d-9B2A-41514C010335}\CDGuid","SUCCESS","Type: REG_SZ, Length: 78, Data: {7ADE9F27-A175-447F-A4B4-B05FA82735E1}" "18:39:58.3636367","hpzmsi01.exe","3824","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{348082C7-A032-4e1d-9B2A-41514C010335}","SUCCESS","Desired Access: All Access" "18:39:58.3636950","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{348082C7-A032-4e1d-9B2A-41514C010335}\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1006633115" "18:39:58.3640814","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{348082C7-A032-4e1d-9B2A-41514C010335}\Version_STR","SUCCESS","Type: REG_SZ, Length: 14, Data: 60.0.1" "18:39:58.3642884","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{348082C7-A032-4e1d-9B2A-41514C010335}\Filename","SUCCESS","Type: REG_SZ, Length: 58, Data: D:\setup\TrayApp\TrayApp.msi" "18:39:58.3646921","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{348082C7-A032-4e1d-9B2A-41514C010335}\section","SUCCESS","Type: REG_SZ, Length: 24, Data: MSI.TrayApp" "18:40:25.6395603","hpzmsi01.exe","3824","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{3E1BD9D1-80F1-4965-824D-05587BD19FD5}","SUCCESS","Desired Access: All Access" "18:40:25.6414278","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{3E1BD9D1-80F1-4965-824D-05587BD19FD5}\CDGuid","SUCCESS","Type: REG_SZ, Length: 78, Data: {7ADE9F27-A175-447F-A4B4-B05FA82735E1}" "18:40:25.6438890","hpzmsi01.exe","3824","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{3E1BD9D1-80F1-4965-824D-05587BD19FD5}","SUCCESS","Desired Access: All Access" "18:40:25.6439404","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{3E1BD9D1-80F1-4965-824D-05587BD19FD5}\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1006633115" "18:40:25.6443707","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{3E1BD9D1-80F1-4965-824D-05587BD19FD5}\Version_STR","SUCCESS","Type: REG_SZ, Length: 14, Data: 60.0.1" "18:40:25.6445366","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{3E1BD9D1-80F1-4965-824D-05587BD19FD5}\Filename","SUCCESS","Type: REG_SZ, Length: 54, Data: D:\setup\Status\Status.msi" "18:40:25.6449746","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{3E1BD9D1-80F1-4965-824D-05587BD19FD5}\section","SUCCESS","Type: REG_SZ, Length: 22, Data: MSI.Status" "18:40:35.9444554","hpzmsi01.exe","3824","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{68FCE472-CCC6-4113-A478-3D29FC934EA0}","SUCCESS","Desired Access: All Access" "18:40:35.9457327","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{68FCE472-CCC6-4113-A478-3D29FC934EA0}\CDGuid","SUCCESS","Type: REG_SZ, Length: 78, Data: {7ADE9F27-A175-447F-A4B4-B05FA82735E1}" "18:40:35.9487077","hpzmsi01.exe","3824","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{68FCE472-CCC6-4113-A478-3D29FC934EA0}","SUCCESS","Desired Access: All Access" "18:40:35.9487607","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{68FCE472-CCC6-4113-A478-3D29FC934EA0}\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1006633115" "18:40:35.9492309","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{68FCE472-CCC6-4113-A478-3D29FC934EA0}\Version_STR","SUCCESS","Type: REG_SZ, Length: 14, Data: 60.0.1" "18:40:35.9494955","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{68FCE472-CCC6-4113-A478-3D29FC934EA0}\Filename","SUCCESS","Type: REG_SZ, Length: 66, Data: D:\setup\BufferChm\BufferChm.msi" "18:40:35.9500902","hpzmsi01.exe","3824","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{68FCE472-CCC6-4113-A478-3D29FC934EA0}\section","SUCCESS","Type: REG_SZ, Length: 28, Data: MSI.Bufferchm" "18:40:39.7796339","hpzmsi01.exe","1468","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install","SUCCESS","Desired Access: All Access" "18:40:39.8367230","hpzmsi01.exe","1468","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{348082C7-A032-4e1d-9B2A-41514C010335}","SUCCESS","Desired Access: All Access" "18:40:39.8933154","hpzmsi01.exe","1468","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{348082C7-A032-4e1d-9B2A-41514C010335}","SUCCESS","Desired Access: All Access" "18:40:39.8952023","hpzmsi01.exe","1468","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{348082C7-A032-4e1d-9B2A-41514C010335}","SUCCESS","Desired Access: All Access" "18:40:39.8953629","hpzmsi01.exe","1468","RegDeleteValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{348082C7-A032-4e1d-9B2A-41514C010335}\CDGuid","SUCCESS","" "18:40:39.8976135","hpzmsi01.exe","1468","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{3E1BD9D1-80F1-4965-824D-05587BD19FD5}","SUCCESS","Desired Access: All Access" "18:40:39.9074563","hpzmsi01.exe","1468","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{3E1BD9D1-80F1-4965-824D-05587BD19FD5}","SUCCESS","Desired Access: All Access" "18:40:39.9093124","hpzmsi01.exe","1468","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{3E1BD9D1-80F1-4965-824D-05587BD19FD5}","SUCCESS","Desired Access: All Access" "18:40:39.9095370","hpzmsi01.exe","1468","RegDeleteValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{3E1BD9D1-80F1-4965-824D-05587BD19FD5}\CDGuid","SUCCESS","" "18:40:39.9120960","hpzmsi01.exe","1468","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{688F7E20-2234-4ab3-94B2-38BF116B0575}","SUCCESS","Desired Access: All Access" "18:40:39.9143879","hpzmsi01.exe","1468","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{68FCE472-CCC6-4113-A478-3D29FC934EA0}","SUCCESS","Desired Access: All Access" "18:40:39.9257751","hpzmsi01.exe","1468","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{68FCE472-CCC6-4113-A478-3D29FC934EA0}","SUCCESS","Desired Access: All Access" "18:40:39.9277095","hpzmsi01.exe","1468","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{68FCE472-CCC6-4113-A478-3D29FC934EA0}","SUCCESS","Desired Access: All Access" "18:40:39.9278651","hpzmsi01.exe","1468","RegDeleteValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{68FCE472-CCC6-4113-A478-3D29FC934EA0}\CDGuid","SUCCESS","" "18:40:39.9299614","hpzmsi01.exe","1468","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}","SUCCESS","Desired Access: All Access" "18:40:39.9321184","hpzmsi01.exe","1468","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{831FF972-593D-46BB-918D-D4D1B9608E12}","SUCCESS","Desired Access: All Access" "18:40:39.9408718","hpzmsi01.exe","1468","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{831FF972-593D-46BB-918D-D4D1B9608E12}","SUCCESS","Desired Access: All Access" "18:40:39.9427756","hpzmsi01.exe","1468","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{831FF972-593D-46BB-918D-D4D1B9608E12}","SUCCESS","Desired Access: All Access" "18:40:39.9429832","hpzmsi01.exe","1468","RegDeleteValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{831FF972-593D-46BB-918D-D4D1B9608E12}\CDGuid","SUCCESS","" "18:40:39.9460651","hpzmsi01.exe","1468","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{86ABAF46-1F4E-4b45-9E13-6246D83303F3}","SUCCESS","Desired Access: All Access" "18:40:39.9480878","hpzmsi01.exe","1468","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{9716D554-3FBD-4DFD-8AE0-424EFD722D74}","SUCCESS","Desired Access: All Access" "18:40:39.9603069","hpzmsi01.exe","1468","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{9716D554-3FBD-4DFD-8AE0-424EFD722D74}","SUCCESS","Desired Access: All Access" "18:40:39.9622960","hpzmsi01.exe","1468","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{9716D554-3FBD-4DFD-8AE0-424EFD722D74}","SUCCESS","Desired Access: All Access" "18:40:39.9624446","hpzmsi01.exe","1468","RegDeleteValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{9716D554-3FBD-4DFD-8AE0-424EFD722D74}\CDGuid","SUCCESS","" "18:40:39.9647371","hpzmsi01.exe","1468","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{B0564E46-594F-4E69-AEF9-AEE9C73050B8}","SUCCESS","Desired Access: All Access" "18:40:39.9835652","hpzmsi01.exe","1468","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{B0564E46-594F-4E69-AEF9-AEE9C73050B8}","SUCCESS","Desired Access: All Access" "18:40:39.9860702","hpzmsi01.exe","1468","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{B0564E46-594F-4E69-AEF9-AEE9C73050B8}","SUCCESS","Desired Access: All Access" "18:40:39.9862256","hpzmsi01.exe","1468","RegDeleteValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{B0564E46-594F-4E69-AEF9-AEE9C73050B8}\CDGuid","SUCCESS","" "18:40:42.0599682","hpzprl01.exe","3932","RegCreateKey","HKLM\Software\Hewlett-Packard\HP Digital Imaging Monitor-hpqbpl01.dat","SUCCESS","Desired Access: Maximum Allowed" "18:40:42.0602327","hpzprl01.exe","3932","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\HP Digital Imaging Monitor-hpqbpl01.dat\Version","SUCCESS","Type: REG_SZ, Length: 22, Data: 60.0.155.0" "18:40:42.0607378","hpzprl01.exe","3932","RegCreateKey","HKLM\Software\Hewlett-Packard\HP Digital Imaging Monitor-hpqbpl01.dat","SUCCESS","Desired Access: Maximum Allowed" "18:40:42.0607867","hpzprl01.exe","3932","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\HP Digital Imaging Monitor-hpqbpl01.dat\Name","SUCCESS","Type: REG_SZ, Length: 86, Data: Uninstaller for HP Digital Imaging Monitor" "18:40:47.3161080","hpzarp01.exe","1364","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\HP Imaging Device Functions","SUCCESS","Desired Access: All Access" "18:40:47.3165195","hpzarp01.exe","1364","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HP Imaging Device Functions\UninstallString","SUCCESS","Type: REG_SZ, Length: 186, Data: C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat" "18:40:47.3232480","hpzarp01.exe","1364","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HP Imaging Device Functions\DisplayName","SUCCESS","Type: REG_SZ, Length: 64, Data: HP Imaging Device Functions 6.0" "18:40:47.3316678","hpzarp01.exe","1364","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HP Imaging Device Functions\DisplayIcon","SUCCESS","Type: REG_SZ, Length: 146, Data: C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe,0" "18:40:47.3319611","hpzarp01.exe","1364","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HP Imaging Device Functions\DisplayVersion","SUCCESS","Type: REG_SZ, Length: 8, Data: 6.0" "18:40:47.3322774","hpzarp01.exe","1364","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HP Imaging Device Functions\Publisher","SUCCESS","Type: REG_SZ, Length: 6, Data: HP" "18:40:47.3324156","hpzarp01.exe","1364","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HP Imaging Device Functions\URLUpdateInfo","SUCCESS","Type: REG_SZ, Length: 36, Data: http://www.hp.com" "18:40:47.3327774","hpzarp01.exe","1364","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HP Imaging Device Functions\HelpLink","SUCCESS","Type: REG_SZ, Length: 52, Data: http://www.hp.com/support" "18:40:57.8317098","hpzmsi01.exe","1768","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{831FF972-593D-46BB-918D-D4D1B9608E12}","SUCCESS","Desired Access: All Access" "18:40:57.8317908","hpzmsi01.exe","1768","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{831FF972-593D-46BB-918D-D4D1B9608E12}\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 16777216" "18:40:57.8318297","hpzmsi01.exe","1768","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{831FF972-593D-46BB-918D-D4D1B9608E12}\Version_STR","SUCCESS","Type: REG_SZ, Length: 12, Data: 1.0.1" "18:40:57.8318612","hpzmsi01.exe","1768","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{831FF972-593D-46BB-918D-D4D1B9608E12}\Filename","SUCCESS","Type: REG_SZ, Length: 74, Data: D:\setup\QFolder\eSupportQFolder.MSI" "18:40:57.8331502","hpzmsi01.exe","1768","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{831FF972-593D-46BB-918D-D4D1B9608E12}\section","SUCCESS","Type: REG_SZ, Length: 40, Data: MSI.eSupportQfolder" "18:41:09.9092018","hpzmsi01.exe","1768","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{29288FBB-DA46-4AC2-84B9-7A8367FE60DF}","SUCCESS","Desired Access: All Access" "18:41:10.0263533","hpzmsi01.exe","1768","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{29288FBB-DA46-4AC2-84B9-7A8367FE60DF}","SUCCESS","Desired Access: All Access" "18:41:10.5660627","hpzmsi01.exe","1768","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{29288FBB-DA46-4AC2-84B9-7A8367FE60DF}\RefCount","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "18:41:11.0689936","hpzmsi01.exe","1768","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{29288FBB-DA46-4AC2-84B9-7A8367FE60DF}","SUCCESS","Desired Access: All Access" "18:41:11.0690640","hpzmsi01.exe","1768","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{29288FBB-DA46-4AC2-84B9-7A8367FE60DF}\CDGuid","SUCCESS","Type: REG_SZ, Length: 78, Data: {7ADE9F27-A175-447F-A4B4-B05FA82735E1}" "18:41:11.1500531","hpzmsi01.exe","1768","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{29288FBB-DA46-4AC2-84B9-7A8367FE60DF}","SUCCESS","Desired Access: All Access" "18:41:11.1501218","hpzmsi01.exe","1768","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{29288FBB-DA46-4AC2-84B9-7A8367FE60DF}\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1006633115" "18:41:11.1504238","hpzmsi01.exe","1768","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{29288FBB-DA46-4AC2-84B9-7A8367FE60DF}\Version_STR","SUCCESS","Type: REG_SZ, Length: 14, Data: 60.0.1" "18:41:11.1508166","hpzmsi01.exe","1768","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{29288FBB-DA46-4AC2-84B9-7A8367FE60DF}\Filename","SUCCESS","Type: REG_SZ, Length: 102, Data: D:\setup\hpproductassistant\hpproductassistant.msi" "18:41:11.1510208","hpzmsi01.exe","1768","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{29288FBB-DA46-4AC2-84B9-7A8367FE60DF}\section","SUCCESS","Type: REG_SZ, Length: 46, Data: MSI.hpproductassistant" "18:41:25.1591677","hpzmsi01.exe","1768","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{4A0C2FF7-F844-4a11-8546-613C19AD5A0C}","SUCCESS","Desired Access: All Access" "18:41:25.1609989","hpzmsi01.exe","1768","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{4A0C2FF7-F844-4a11-8546-613C19AD5A0C}\CDGuid","SUCCESS","Type: REG_SZ, Length: 78, Data: {7ADE9F27-A175-447F-A4B4-B05FA82735E1}" "18:41:25.1633626","hpzmsi01.exe","1768","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{4A0C2FF7-F844-4a11-8546-613C19AD5A0C}","SUCCESS","Desired Access: All Access" "18:41:25.1634162","hpzmsi01.exe","1768","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{4A0C2FF7-F844-4a11-8546-613C19AD5A0C}\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1006633115" "18:41:25.1638096","hpzmsi01.exe","1768","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{4A0C2FF7-F844-4a11-8546-613C19AD5A0C}\Version_STR","SUCCESS","Type: REG_SZ, Length: 14, Data: 60.0.1" "18:41:25.1639738","hpzmsi01.exe","1768","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{4A0C2FF7-F844-4a11-8546-613C19AD5A0C}\Filename","SUCCESS","Type: REG_SZ, Length: 54, Data: D:\setup\WebReg\WebReg.msi" "18:41:25.1644504","hpzmsi01.exe","1768","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{4A0C2FF7-F844-4a11-8546-613C19AD5A0C}\section","SUCCESS","Type: REG_SZ, Length: 22, Data: MSI.WebReg" "18:41:50.2562252","hpzmsi01.exe","1768","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{65B97CFB-5CFB-4764-BADC-0B3A756E761C}","SUCCESS","Desired Access: All Access" "18:41:50.2586680","hpzmsi01.exe","1768","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{65B97CFB-5CFB-4764-BADC-0B3A756E761C}\CDGuid","SUCCESS","Type: REG_SZ, Length: 78, Data: {7ADE9F27-A175-447F-A4B4-B05FA82735E1}" "18:41:50.2625755","hpzmsi01.exe","1768","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{65B97CFB-5CFB-4764-BADC-0B3A756E761C}","SUCCESS","Desired Access: All Access" "18:41:50.2626358","hpzmsi01.exe","1768","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{65B97CFB-5CFB-4764-BADC-0B3A756E761C}\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1006633115" "18:41:50.2641709","hpzmsi01.exe","1768","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{65B97CFB-5CFB-4764-BADC-0B3A756E761C}\Version_STR","SUCCESS","Type: REG_SZ, Length: 14, Data: 60.0.1" "18:41:50.2646850","hpzmsi01.exe","1768","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{65B97CFB-5CFB-4764-BADC-0B3A756E761C}\Filename","SUCCESS","Type: REG_SZ, Length: 86, Data: D:\setup\SolutionCenter\SolutionCenter.msi" "18:41:50.2653088","hpzmsi01.exe","1768","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{65B97CFB-5CFB-4764-BADC-0B3A756E761C}\section","SUCCESS","Type: REG_SZ, Length: 38, Data: MSI.SolutionCenter" "18:41:53.6558433","hpzmsi01.exe","1876","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install","SUCCESS","Desired Access: All Access" "18:41:53.6584954","hpzmsi01.exe","1876","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{29288FBB-DA46-4AC2-84B9-7A8367FE60DF}","SUCCESS","Desired Access: All Access" "18:41:53.6756246","hpzmsi01.exe","1876","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{29288FBB-DA46-4AC2-84B9-7A8367FE60DF}","SUCCESS","Desired Access: All Access" "18:41:53.6794176","hpzmsi01.exe","1876","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{29288FBB-DA46-4AC2-84B9-7A8367FE60DF}","SUCCESS","Desired Access: All Access" "18:41:53.6796562","hpzmsi01.exe","1876","RegDeleteValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{29288FBB-DA46-4AC2-84B9-7A8367FE60DF}\CDGuid","SUCCESS","" "18:41:53.6856100","hpzmsi01.exe","1876","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{348082C7-A032-4e1d-9B2A-41514C010335}","SUCCESS","Desired Access: All Access" "18:41:53.6885444","hpzmsi01.exe","1876","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{3E1BD9D1-80F1-4965-824D-05587BD19FD5}","SUCCESS","Desired Access: All Access" "18:41:53.6940066","hpzmsi01.exe","1876","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{4A0C2FF7-F844-4a11-8546-613C19AD5A0C}","SUCCESS","Desired Access: All Access" "18:41:53.7409268","hpzmsi01.exe","1876","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{4A0C2FF7-F844-4a11-8546-613C19AD5A0C}","SUCCESS","Desired Access: All Access" "18:41:53.7428508","hpzmsi01.exe","1876","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{4A0C2FF7-F844-4a11-8546-613C19AD5A0C}","SUCCESS","Desired Access: All Access" "18:41:53.7430153","hpzmsi01.exe","1876","RegDeleteValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{4A0C2FF7-F844-4a11-8546-613C19AD5A0C}\CDGuid","SUCCESS","" "18:41:53.7452438","hpzmsi01.exe","1876","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{65B97CFB-5CFB-4764-BADC-0B3A756E761C}","SUCCESS","Desired Access: All Access" "18:41:53.7541352","hpzmsi01.exe","1876","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{65B97CFB-5CFB-4764-BADC-0B3A756E761C}","SUCCESS","Desired Access: All Access" "18:41:53.7560678","hpzmsi01.exe","1876","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{65B97CFB-5CFB-4764-BADC-0B3A756E761C}","SUCCESS","Desired Access: All Access" "18:41:53.7562176","hpzmsi01.exe","1876","RegDeleteValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{65B97CFB-5CFB-4764-BADC-0B3A756E761C}\CDGuid","SUCCESS","" "18:41:53.7582812","hpzmsi01.exe","1876","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{688F7E20-2234-4ab3-94B2-38BF116B0575}","SUCCESS","Desired Access: All Access" "18:41:53.7604178","hpzmsi01.exe","1876","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{68FCE472-CCC6-4113-A478-3D29FC934EA0}","SUCCESS","Desired Access: All Access" "18:41:53.7624876","hpzmsi01.exe","1876","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}","SUCCESS","Desired Access: All Access" "18:41:53.7659157","hpzmsi01.exe","1876","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{831FF972-593D-46BB-918D-D4D1B9608E12}","SUCCESS","Desired Access: All Access" "18:41:53.7707487","hpzmsi01.exe","1876","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{86ABAF46-1F4E-4b45-9E13-6246D83303F3}","SUCCESS","Desired Access: All Access" "18:41:53.7728884","hpzmsi01.exe","1876","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{9716D554-3FBD-4DFD-8AE0-424EFD722D74}","SUCCESS","Desired Access: All Access" "18:41:53.7749040","hpzmsi01.exe","1876","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{B0564E46-594F-4E69-AEF9-AEE9C73050B8}","SUCCESS","Desired Access: All Access" "18:41:56.3356540","hpzprl01.exe","3024","RegCreateKey","HKLM\Software\Hewlett-Packard\HP e-Support-hpqbpl05.dat","SUCCESS","Desired Access: Maximum Allowed" "18:41:56.3359857","hpzprl01.exe","3024","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\HP e-Support-hpqbpl05.dat\Version","SUCCESS","Type: REG_SZ, Length: 22, Data: 60.0.155.0" "18:41:56.3367237","hpzprl01.exe","3024","RegCreateKey","HKLM\Software\Hewlett-Packard\HP e-Support-hpqbpl05.dat","SUCCESS","Desired Access: Maximum Allowed" "18:41:56.3367718","hpzprl01.exe","3024","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\HP e-Support-hpqbpl05.dat\Name","SUCCESS","Type: REG_SZ, Length: 58, Data: Uninstaller for HP e-Support" "18:42:01.1574722","hpzarp01.exe","3612","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\HP Solution Center & Imaging Support Tools","SUCCESS","Desired Access: All Access" "18:42:01.1578680","hpzarp01.exe","3612","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HP Solution Center & Imaging Support Tools\UninstallString","SUCCESS","Type: REG_SZ, Length: 160, Data: C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat" "18:42:01.1651533","hpzarp01.exe","3612","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HP Solution Center & Imaging Support Tools\DisplayName","SUCCESS","Type: REG_SZ, Length: 98, Data: HP Solution Center and Imaging Support Tools 6.0" "18:42:01.1727336","hpzarp01.exe","3612","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HP Solution Center & Imaging Support Tools\DisplayIcon","SUCCESS","Type: REG_SZ, Length: 120, Data: C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe,0" "18:42:01.1729831","hpzarp01.exe","3612","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HP Solution Center & Imaging Support Tools\DisplayVersion","SUCCESS","Type: REG_SZ, Length: 8, Data: 6.0" "18:42:01.1734714","hpzarp01.exe","3612","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HP Solution Center & Imaging Support Tools\Publisher","SUCCESS","Type: REG_SZ, Length: 6, Data: HP" "18:42:01.1736754","hpzarp01.exe","3612","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HP Solution Center & Imaging Support Tools\URLUpdateInfo","SUCCESS","Type: REG_SZ, Length: 36, Data: http://www.hp.com" "18:42:01.1741008","hpzarp01.exe","3612","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HP Solution Center & Imaging Support Tools\HelpLink","SUCCESS","Type: REG_SZ, Length: 52, Data: http://www.hp.com/support" "18:42:54.2800216","hpzmsi01.exe","3684","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{1DBA2633-55BD-42E2-BA81-EA4EBEC2CCF4}","SUCCESS","Desired Access: All Access" "18:42:54.2810440","hpzmsi01.exe","3684","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{1DBA2633-55BD-42E2-BA81-EA4EBEC2CCF4}\CDGuid","SUCCESS","Type: REG_SZ, Length: 78, Data: {7ADE9F27-A175-447F-A4B4-B05FA82735E1}" "18:42:54.2882408","hpzmsi01.exe","3684","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{1DBA2633-55BD-42E2-BA81-EA4EBEC2CCF4}","SUCCESS","Desired Access: All Access" "18:42:54.2883011","hpzmsi01.exe","3684","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{1DBA2633-55BD-42E2-BA81-EA4EBEC2CCF4}\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 17301504" "18:42:54.2889607","hpzmsi01.exe","3684","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{1DBA2633-55BD-42E2-BA81-EA4EBEC2CCF4}\Version_STR","SUCCESS","Type: REG_SZ, Length: 12, Data: 1.8.1" "18:42:54.2891705","hpzmsi01.exe","3684","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{1DBA2633-55BD-42E2-BA81-EA4EBEC2CCF4}\Filename","SUCCESS","Type: REG_SZ, Length: 94, Data: D:\setup\ImageZoneExpress\ImageZoneExpress.msi" "18:42:54.2896887","hpzmsi01.exe","3684","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{1DBA2633-55BD-42E2-BA81-EA4EBEC2CCF4}\section","SUCCESS","Type: REG_SZ, Length: 42, Data: MSI.imagezoneexpress" "18:43:32.6084326","hpzmsi01.exe","576","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{7BB3DC99-71DA-4FCB-B0ED-ACA161DBCA4B}","SUCCESS","Desired Access: All Access" "18:43:32.6141280","hpzmsi01.exe","576","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{7BB3DC99-71DA-4FCB-B0ED-ACA161DBCA4B}\CDGuid","SUCCESS","Type: REG_SZ, Length: 78, Data: {7ADE9F27-A175-447F-A4B4-B05FA82735E1}" "18:43:32.6181570","hpzmsi01.exe","576","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{7BB3DC99-71DA-4FCB-B0ED-ACA161DBCA4B}","SUCCESS","Desired Access: All Access" "18:43:32.6182137","hpzmsi01.exe","576","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{7BB3DC99-71DA-4FCB-B0ED-ACA161DBCA4B}\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 50331654" "18:43:32.6187367","hpzmsi01.exe","576","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{7BB3DC99-71DA-4FCB-B0ED-ACA161DBCA4B}\Version_STR","SUCCESS","Type: REG_SZ, Length: 12, Data: 3.0.1" "18:43:32.6189521","hpzmsi01.exe","576","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{7BB3DC99-71DA-4FCB-B0ED-ACA161DBCA4B}\Filename","SUCCESS","Type: REG_SZ, Length: 94, Data: D:\setup\HPSoftwareUpdate\HPSoftwareUpdate.msi" "18:43:32.6195097","hpzmsi01.exe","576","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{7BB3DC99-71DA-4FCB-B0ED-ACA161DBCA4B}\section","SUCCESS","Type: REG_SZ, Length: 42, Data: MSI.HPSoftwareUpdate" "18:43:36.7798879","hpzmsi01.exe","3208","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install","SUCCESS","Desired Access: All Access" "18:43:36.7931401","hpzmsi01.exe","3208","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{1DBA2633-55BD-42E2-BA81-EA4EBEC2CCF4}","SUCCESS","Desired Access: All Access" "18:43:36.8245084","hpzmsi01.exe","3208","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{1DBA2633-55BD-42E2-BA81-EA4EBEC2CCF4}","SUCCESS","Desired Access: All Access" "18:43:36.8422128","hpzmsi01.exe","3208","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{1DBA2633-55BD-42E2-BA81-EA4EBEC2CCF4}","SUCCESS","Desired Access: All Access" "18:43:36.8423894","hpzmsi01.exe","3208","RegDeleteValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{1DBA2633-55BD-42E2-BA81-EA4EBEC2CCF4}\CDGuid","SUCCESS","" "18:43:36.8469271","hpzmsi01.exe","3208","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{29288FBB-DA46-4AC2-84B9-7A8367FE60DF}","SUCCESS","Desired Access: All Access" "18:43:36.8528360","hpzmsi01.exe","3208","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{348082C7-A032-4e1d-9B2A-41514C010335}","SUCCESS","Desired Access: All Access" "18:43:36.8626590","hpzmsi01.exe","3208","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{3E1BD9D1-80F1-4965-824D-05587BD19FD5}","SUCCESS","Desired Access: All Access" "18:43:36.8670389","hpzmsi01.exe","3208","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{4A0C2FF7-F844-4a11-8546-613C19AD5A0C}","SUCCESS","Desired Access: All Access" "18:43:36.8753768","hpzmsi01.exe","3208","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{65B97CFB-5CFB-4764-BADC-0B3A756E761C}","SUCCESS","Desired Access: All Access" "18:43:36.9065207","hpzmsi01.exe","3208","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{688F7E20-2234-4ab3-94B2-38BF116B0575}","SUCCESS","Desired Access: All Access" "18:43:36.9117507","hpzmsi01.exe","3208","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{68FCE472-CCC6-4113-A478-3D29FC934EA0}","SUCCESS","Desired Access: All Access" "18:43:36.9312275","hpzmsi01.exe","3208","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}","SUCCESS","Desired Access: All Access" "18:43:36.9367084","hpzmsi01.exe","3208","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{7BB3DC99-71DA-4FCB-B0ED-ACA161DBCA4B}","SUCCESS","Desired Access: All Access" "18:43:37.4989874","hpzmsi01.exe","3208","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{7BB3DC99-71DA-4FCB-B0ED-ACA161DBCA4B}","SUCCESS","Desired Access: All Access" "18:43:37.5143536","hpzmsi01.exe","3208","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{7BB3DC99-71DA-4FCB-B0ED-ACA161DBCA4B}","SUCCESS","Desired Access: All Access" "18:43:37.5145989","hpzmsi01.exe","3208","RegDeleteValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{7BB3DC99-71DA-4FCB-B0ED-ACA161DBCA4B}\CDGuid","SUCCESS","" "18:43:37.5343011","hpzmsi01.exe","3208","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{831FF972-593D-46BB-918D-D4D1B9608E12}","SUCCESS","Desired Access: All Access" "18:43:37.5400116","hpzmsi01.exe","3208","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{86ABAF46-1F4E-4b45-9E13-6246D83303F3}","SUCCESS","Desired Access: All Access" "18:43:37.5431815","hpzmsi01.exe","3208","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{9716D554-3FBD-4DFD-8AE0-424EFD722D74}","SUCCESS","Desired Access: All Access" "18:43:37.5489217","hpzmsi01.exe","3208","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{B0564E46-594F-4E69-AEF9-AEE9C73050B8}","SUCCESS","Desired Access: All Access" "18:43:43.8627585","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:43:43.9618772","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\root","SUCCESS","Desired Access: All Access" "18:43:43.9620663","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\root","SUCCESS","Desired Access: All Access" "18:43:43.9623130","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Desired Access: All Access" "18:43:43.9624287","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Desired Access: All Access" "18:43:43.9626293","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Desired Access: All Access" "18:43:43.9631458","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\root","SUCCESS","Desired Access: All Access" "18:43:43.9632341","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\root","SUCCESS","Desired Access: All Access" "18:43:43.9633646","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Desired Access: All Access" "18:43:43.9646007","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS","Desired Access: All Access" "18:43:43.9647091","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS","Desired Access: All Access" "18:43:43.9649324","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Desired Access: All Access" "18:43:43.9650011","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.0197826","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.0199754","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.0201335","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\root","SUCCESS","Desired Access: All Access" "18:43:44.0201684","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\root\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.0202885","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\root\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.0203947","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\root\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.0205900","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\root","SUCCESS","Desired Access: All Access" "18:43:44.0207129","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\root","SUCCESS","Desired Access: All Access" "18:43:44.0207755","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.0208833","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.0211110","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.0215465","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\ca","SUCCESS","Desired Access: All Access" "18:43:44.0216865","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\ca","SUCCESS","Desired Access: All Access" "18:43:44.0217725","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.0219047","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.0220069","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.0222489","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\ca","SUCCESS","Desired Access: All Access" "18:43:44.0222938","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\ca\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.0224162","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\ca\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.0225274","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\ca\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.0227076","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\ca","SUCCESS","Desired Access: All Access" "18:43:44.0228389","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\ca","SUCCESS","Desired Access: All Access" "18:43:44.0228981","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.0272299","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.0275104","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.0277158","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\ca","SUCCESS","Desired Access: All Access" "18:43:44.0277596","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\ca\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.0278560","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\ca\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.0279476","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\ca\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.0281099","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\ca","SUCCESS","Desired Access: All Access" "18:43:44.0281708","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\ca","SUCCESS","Desired Access: All Access" "18:43:44.0282312","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.0283334","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.0296361","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.0301292","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\disallowed","SUCCESS","Desired Access: All Access" "18:43:44.0304127","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\disallowed","SUCCESS","Desired Access: All Access" "18:43:44.0304977","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.0306044","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.0306988","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.0309284","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed","SUCCESS","Desired Access: All Access" "18:43:44.0310103","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.0312486","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.0313626","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.0326784","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\disallowed","SUCCESS","Desired Access: All Access" "18:43:44.0330268","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\disallowed","SUCCESS","Desired Access: All Access" "18:43:44.0330871","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.0337417","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.0338408","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.0339719","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\disallowed","SUCCESS","Desired Access: All Access" "18:43:44.0340098","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.0341076","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.0342688","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.0344906","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\disallowed","SUCCESS","Desired Access: All Access" "18:43:44.0345515","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\disallowed","SUCCESS","Desired Access: All Access" "18:43:44.0346085","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.0347057","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.0348027","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.0349706","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.0350748","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.0351606","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.0405917","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed","SUCCESS","Desired Access: All Access" "18:43:44.0406400","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.0408085","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.0409174","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.0412038","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.0417027","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.0417977","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.0419606","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\disallowed","SUCCESS","Desired Access: All Access" "18:43:44.0419913","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.0420857","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.0421751","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.0423162","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.0425118","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.0426067","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.0428990","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: All Access" "18:43:44.0430417","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: All Access" "18:43:44.0431292","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.0432345","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.0433429","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.0436150","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: All Access" "18:43:44.0436594","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.0437756","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.0439455","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.0443078","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: All Access" "18:43:44.0443712","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: All Access" "18:43:44.0444268","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.0445232","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.0446207","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.0447967","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: All Access" "18:43:44.0448419","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.0449557","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.0450607","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.0452289","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\trust","SUCCESS","Desired Access: All Access" "18:43:44.0452928","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\trust","SUCCESS","Desired Access: All Access" "18:43:44.0454188","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.0455169","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.0456138","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.0459482","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\my","SUCCESS","Desired Access: All Access" "18:43:44.0630314","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon","SUCCESS","Desired Access: Read/Write" "18:43:44.1059290","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1060483","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1061450","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1068990","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1078466","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1080142","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1081958","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1275762","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1276810","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1291434","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\root","SUCCESS","Desired Access: All Access" "18:43:44.1291834","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\root\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1292815","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\root\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1293725","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\root\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1295527","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1296569","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1297505","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1299729","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1300776","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1301751","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1303646","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: All Access" "18:43:44.1304025","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1305076","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1306744","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1308210","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1309118","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1310004","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1310948","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: All Access" "18:43:44.1311283","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1312253","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1313217","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1315069","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1316007","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1316887","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1317963","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1318893","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1320460","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1321930","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\ca","SUCCESS","Desired Access: All Access" "18:43:44.1322268","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\ca\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1323366","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\ca\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1324352","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\ca\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1326255","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1349042","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1352199","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1354191","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\ca","SUCCESS","Desired Access: All Access" "18:43:44.1354959","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\ca\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1355918","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\ca\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1356817","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\ca\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1358267","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1359614","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1360591","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1652106","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.1655095","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.1656364","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1657473","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1658448","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1660808","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.1661166","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1662280","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1663367","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1665697","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.1668223","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.1668809","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1674229","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1675190","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1676486","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.1676824","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1677755","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1679017","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1681238","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.1681861","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.1682442","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1683353","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1684286","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1685892","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1686904","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1687800","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1689262","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.1689588","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1692999","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1694827","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1697173","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1712122","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1713474","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1714712","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.1715033","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1715963","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1716852","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.1718388","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.1719372","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.1720305","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.5334392","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:43:44.5687555","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.5693187","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.5694069","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.5695514","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.5696452","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.5713723","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.5714105","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.5715240","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.5716326","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.5718341","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.5720528","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.5721115","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.5727984","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.5728934","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.5730633","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.5730957","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.5731884","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.5732778","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.5734220","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.5734843","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.5735421","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.5736351","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.5738930","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.5741271","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.5742330","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.5743232","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.5744693","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.5745031","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.5746135","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.5747210","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.5749015","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.5766260","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.5767420","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.5770772","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.5771135","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.5772088","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.5785425","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.5787785","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.5788774","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.5789710","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.7446630","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.7449522","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.7450402","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.7451502","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.7452424","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.7456048","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.7456427","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.7457531","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.7458858","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.7460473","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.7462504","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.7463068","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.7467904","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.7468873","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.7470862","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.7471195","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.7485266","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.7486272","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.7488180","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.7488834","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.7489426","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.7490368","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.7491312","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.7493008","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.7494075","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.7494985","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.7496466","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.7496807","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.7498637","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.7500131","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.7501956","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.7517416","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.7518396","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.7519592","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:44.7519913","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.7520844","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.7522017","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.7523581","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:44.7524540","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:44.7525470","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:44.9944576","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:43:45.0115975","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.0118900","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.0120255","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.0121702","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.0122624","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.0125311","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.0125694","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.0126834","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.0137860","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.0139785","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.0142981","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.0144023","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.0149041","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.0149996","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.0151290","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.0151611","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.0152544","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.0153435","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.0155528","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.0156151","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.0156748","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.0159327","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.0160296","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.0161950","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.0162973","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.0163875","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.0165333","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.0165666","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.0177785","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.0179072","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.0181254","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.0185657","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.0186621","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.0187791","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.0188107","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.0189032","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.0189920","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.0191999","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.0193650","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.0194600","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.0357606","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.0360621","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.0362302","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.0364082","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.0365032","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.0379508","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.0379914","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.0381053","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.0382674","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.0384325","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.0386825","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.0387459","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.0392619","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.0393572","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.0394854","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.0395173","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.0396089","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.0396980","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.0444092","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.0444768","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.0445358","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.0446319","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.0447249","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.0449590","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.0450724","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.0451632","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.0453118","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.0453465","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.0454571","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.0456041","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.0457876","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.0462558","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.0464195","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.0465413","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.0465721","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.0466925","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.0470417","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.0472015","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.0473018","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.0473953","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.4492238","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:43:45.4638924","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.4641969","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.4643718","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.4645674","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.4646601","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.4648917","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.4649303","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.4650414","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.4651493","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.4653088","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.4655597","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.4656588","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.4875708","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.4876759","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.4878186","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.4878530","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.4879480","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.4881190","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.4883075","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.4883695","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.4884307","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.4885232","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.4886207","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.4887892","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.4888928","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.4889833","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.4891331","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.4891677","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.4892808","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.4894943","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.4896840","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.4901041","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.4901952","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.4903106","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.4903410","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.4904296","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.4905497","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.4906905","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.4907858","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.4909450","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.5340606","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.5343500","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.5344385","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.5345506","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.5346425","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.5348702","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.5349067","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.5350551","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.5351649","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.5354314","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.5356345","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.5356904","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.5361756","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.5362720","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.5364002","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.5364312","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.5365248","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.5366799","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.5368743","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.5369386","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.5369961","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.5370886","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.5371822","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.5374057","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.5375074","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.5375970","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.5377426","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.5377755","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.5378870","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.5379946","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.5382443","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.5386975","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.5387882","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.5389028","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.5389338","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.5390224","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.5391109","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.5392512","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.5393464","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.5394397","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.7037581","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:43:45.7451553","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.7454617","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.7455500","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.7457375","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.7458355","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.7460964","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.7461367","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.7462501","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.7464328","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.7465968","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.7468071","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.7468669","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.7491519","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.7492739","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.7495835","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.7496190","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.7497125","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.7498017","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.7499480","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.7500092","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.7500679","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.7501643","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.7502573","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.7504260","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.7505325","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.7506604","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.7508158","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.7509183","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.7510649","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.7511719","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.7513544","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.7518022","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.7518989","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.7520165","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.7520475","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.7521704","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.7522598","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.7524721","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.7525690","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.7526610","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.8024997","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.8028578","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.8030294","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.8031813","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.8032741","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.8037649","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.8038013","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.8039097","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.8040139","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.8041753","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.8044184","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.8044754","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.8050238","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.8051187","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.8052464","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.8052783","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.8054037","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.8056722","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.8058186","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.8058800","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.8059373","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.8060289","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.8061225","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.8063485","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.8064508","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.8065709","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.8067187","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.8067516","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.8068614","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.8069679","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.8071469","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.8075629","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.8077540","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.8078727","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:45.8079037","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.8079929","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.8080814","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:45.8082217","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:45.8083164","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:45.8084091","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.1182795","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:43:46.1318402","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.1321349","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.1322234","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.1324140","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.1325076","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.1327774","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.1328140","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.1329230","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.1330272","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.1331875","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.1333934","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.1334507","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.1341173","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.1342125","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.1343416","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.1343734","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.1344659","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.1345547","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.1347034","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.1347643","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.1348500","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.1349456","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.1350741","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.1352395","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.1354107","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.1355015","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.1356473","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.1356803","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.1357898","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.1358963","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.1361158","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.1365547","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.1366452","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.1368277","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.1368601","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.1369503","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.1370400","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.1372115","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.1373076","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.1373995","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.1634274","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.1637210","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.1638104","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.1639208","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.1640121","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.1644194","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.1644558","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.1646027","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.1647077","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.1648701","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.1650726","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.1651290","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.1656679","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.1659406","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.1660761","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.1661076","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.1662007","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.1662895","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.1664325","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.1664937","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.1665516","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.1666432","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.1667365","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.1669429","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.1670483","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.1671385","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.1674542","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.1674877","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.1676011","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.1677095","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.1678900","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.1683736","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.1684644","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.1685811","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.1686127","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.1687027","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.1711653","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.1714910","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.1715980","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.1716930","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.6000974","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:43:46.6140632","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.6143554","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.6144437","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.6145591","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.6146515","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.6148786","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.6149152","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.6150566","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.6151625","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.6153985","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.6156030","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.6157050","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.6161950","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.6162911","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.6164199","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.6164517","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.6165439","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.6166333","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.6168465","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.6169085","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.6169675","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.6170594","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.6171563","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.6176228","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.6178712","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.6179623","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.6181089","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.6181427","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.6182539","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.6183972","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.6186531","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.6190758","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.6191669","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.6192814","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.6193124","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.6194018","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.6194898","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.6196703","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.6197645","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.6198575","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.6476166","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.6479239","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.6481211","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.6482698","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.6483625","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.6485927","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.6486301","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.6487408","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.6488483","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.6490076","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.6493132","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.6493746","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.6499359","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.6500418","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.6501700","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.6502018","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.6502938","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.6504217","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.6505673","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.6506279","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.6506851","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.6507804","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.6508743","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.6511048","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.6512095","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.6512992","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.6514671","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.6515070","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.6516191","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.6517518","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.6519308","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.6523474","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.6525114","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.6526653","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:46.6526971","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.6527907","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.6528793","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:46.6530198","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:46.6531170","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:46.6532098","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.4163258","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:43:47.4322711","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.4325644","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.4326580","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.4327675","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.4328597","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.4331276","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.4331642","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.4333855","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.4334902","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.4336523","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.4339062","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.4339629","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.4344426","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.4345373","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.4348851","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.4349242","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.4350217","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.4351103","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.4352550","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.4353561","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.4354178","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.4355156","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.4356092","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.4357707","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.4358735","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.4359623","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.4361090","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.4361431","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.4363199","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.4364613","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.4366451","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.4370644","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.4372170","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.4373390","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.4373700","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.4374586","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.4375472","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.4377285","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.4378958","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.4379891","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.5010441","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.5013441","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.5014335","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.5015902","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.5016838","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.5028359","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.5028761","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.5029901","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.5031379","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.5032997","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.5035114","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.5035715","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.5041369","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.5042339","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.5043621","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.5043942","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.5044858","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.5045794","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.5047225","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.5047831","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.5048406","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.5049745","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.5050694","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.5052379","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.5053446","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.5055047","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.5057083","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.5057421","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.5058545","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.5059612","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.5061838","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.5065990","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.5066931","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.5068076","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.5068387","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.5069982","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.5070884","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.5072683","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.5073667","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.5074602","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.6941549","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:43:47.7099622","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.7102536","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.7103771","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.7104883","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.7106551","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.7108853","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.7109213","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.7110772","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.7111839","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.7113462","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.7115809","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.7116395","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.7121564","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.7122528","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.7123813","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.7124472","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.7125760","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.7126712","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.7128165","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.7128777","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.7129347","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.7130269","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.7131207","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.7132814","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.7133839","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.7135429","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.7137292","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.7137641","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.7138767","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.7139829","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.7141642","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.7145835","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.7146732","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.7147874","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.7148179","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.7150081","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.7150995","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.7152425","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.7153372","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.7154294","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.7696642","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.7699738","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.7700629","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.7701780","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.7702702","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.7704998","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.7705378","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.7706490","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.7707951","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.7710317","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.7712424","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.7713030","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.7717776","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.7719377","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.7720752","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.7721067","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.7721995","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.7722897","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.7725029","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.7725652","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.7726241","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.7727180","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.7728116","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.7729705","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.7731029","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.7731940","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.7733410","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.7733756","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.7734851","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.7735924","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.7738324","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.7743126","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.7744093","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.7745224","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:47.7745531","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.7746450","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.7747328","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:47.7748736","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:47.7749694","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:47.7750619","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:48.0573217","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read" "18:43:48.0715199","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:48.0718261","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:48.0719203","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:48.0720764","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:48.0721692","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:48.0724022","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:48.0724401","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:48.0725519","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:48.0726614","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:48.0729184","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:48.0731676","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:48.0732302","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:48.0738468","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:48.0739423","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:48.0740756","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:48.0741121","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:48.0742052","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:48.0743348","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:48.0745477","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:48.0746091","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:48.0746659","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:48.0747603","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:48.0748536","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:48.0750215","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:48.0751279","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:48.0752173","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:48.0764314","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:48.0764705","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:48.0766303","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:48.0767407","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:48.0769309","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:48.0774525","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:48.0775497","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:48.0777285","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:48.0777623","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:48.0778573","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:48.0779487","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:48.0780911","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:48.0781889","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:48.0782822","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:48.0983420","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:48.0986315","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:48.0990226","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:48.0991374","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:48.0992313","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:48.0996106","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:48.0996470","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:48.0997548","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:48.0998587","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:48.1000199","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:48.1002222","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:48.1002783","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:48.1010105","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:48.1011125","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:48.1012413","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:48.1012729","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:48.1013653","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:48.1014570","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:48.1016003","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:48.1017006","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:48.1017584","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:48.1018512","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:48.1019447","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:48.1021079","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:48.1022104","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:48.1023009","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:48.1025155","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:48.1025487","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:48.1026627","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:48.1028071","hpzprl01.exe","3248","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:48.1030147","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:48.1034332","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:48.1035237","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:48.1036385","hpzprl01.exe","3248","RegCreateKey","HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: All Access" "18:43:48.1036695","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:48.1038249","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:48.1039562","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:48.1041006","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: All Access" "18:43:48.1041950","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: All Access" "18:43:48.1042878","hpzprl01.exe","3248","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: All Access" "18:43:57.0253208","hpzmsi01.exe","2116","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install","SUCCESS","Desired Access: All Access" "18:43:57.0272883","hpzmsi01.exe","2116","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{1DBA2633-55BD-42E2-BA81-EA4EBEC2CCF4}","SUCCESS","Desired Access: All Access" "18:43:57.0299797","hpzmsi01.exe","2116","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{29288FBB-DA46-4AC2-84B9-7A8367FE60DF}","SUCCESS","Desired Access: All Access" "18:43:57.0320392","hpzmsi01.exe","2116","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{348082C7-A032-4e1d-9B2A-41514C010335}","SUCCESS","Desired Access: All Access" "18:43:57.0340788","hpzmsi01.exe","2116","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{3E1BD9D1-80F1-4965-824D-05587BD19FD5}","SUCCESS","Desired Access: All Access" "18:43:57.0360341","hpzmsi01.exe","2116","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{4A0C2FF7-F844-4a11-8546-613C19AD5A0C}","SUCCESS","Desired Access: All Access" "18:43:57.0381358","hpzmsi01.exe","2116","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{65B97CFB-5CFB-4764-BADC-0B3A756E761C}","SUCCESS","Desired Access: All Access" "18:43:57.0401427","hpzmsi01.exe","2116","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{688F7E20-2234-4ab3-94B2-38BF116B0575}","SUCCESS","Desired Access: All Access" "18:43:57.0422779","hpzmsi01.exe","2116","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{68FCE472-CCC6-4113-A478-3D29FC934EA0}","SUCCESS","Desired Access: All Access" "18:43:57.0452968","hpzmsi01.exe","2116","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}","SUCCESS","Desired Access: All Access" "18:43:57.0472453","hpzmsi01.exe","2116","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{7BB3DC99-71DA-4FCB-B0ED-ACA161DBCA4B}","SUCCESS","Desired Access: All Access" "18:43:57.0491833","hpzmsi01.exe","2116","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{831FF972-593D-46BB-918D-D4D1B9608E12}","SUCCESS","Desired Access: All Access" "18:43:57.0514224","hpzmsi01.exe","2116","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{86ABAF46-1F4E-4b45-9E13-6246D83303F3}","SUCCESS","Desired Access: All Access" "18:43:57.0534285","hpzmsi01.exe","2116","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{9716D554-3FBD-4DFD-8AE0-424EFD722D74}","SUCCESS","Desired Access: All Access" "18:43:57.0552866","hpzmsi01.exe","2116","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{B0564E46-594F-4E69-AEF9-AEE9C73050B8}","SUCCESS","Desired Access: All Access" "18:44:06.4135924","hpzmsi01.exe","3612","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install","SUCCESS","Desired Access: All Access" "18:44:06.4616212","hpzmsi01.exe","3612","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{1DBA2633-55BD-42E2-BA81-EA4EBEC2CCF4}","SUCCESS","Desired Access: All Access" "18:44:06.5224532","hpzmsi01.exe","3612","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{29288FBB-DA46-4AC2-84B9-7A8367FE60DF}","SUCCESS","Desired Access: All Access" "18:44:06.5458727","hpzmsi01.exe","3612","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{348082C7-A032-4e1d-9B2A-41514C010335}","SUCCESS","Desired Access: All Access" "18:44:06.5514253","hpzmsi01.exe","3612","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{3E1BD9D1-80F1-4965-824D-05587BD19FD5}","SUCCESS","Desired Access: All Access" "18:44:06.5547607","hpzmsi01.exe","3612","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{4A0C2FF7-F844-4a11-8546-613C19AD5A0C}","SUCCESS","Desired Access: All Access" "18:44:06.5582879","hpzmsi01.exe","3612","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{65B97CFB-5CFB-4764-BADC-0B3A756E761C}","SUCCESS","Desired Access: All Access" "18:44:06.5637931","hpzmsi01.exe","3612","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{688F7E20-2234-4ab3-94B2-38BF116B0575}","SUCCESS","Desired Access: All Access" "18:44:06.5920964","hpzmsi01.exe","3612","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{68FCE472-CCC6-4113-A478-3D29FC934EA0}","SUCCESS","Desired Access: All Access" "18:44:06.6166328","hpzmsi01.exe","3612","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}","SUCCESS","Desired Access: All Access" "18:44:06.6211968","hpzmsi01.exe","3612","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{7BB3DC99-71DA-4FCB-B0ED-ACA161DBCA4B}","SUCCESS","Desired Access: All Access" "18:44:06.6282108","hpzmsi01.exe","3612","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{831FF972-593D-46BB-918D-D4D1B9608E12}","SUCCESS","Desired Access: All Access" "18:44:06.6318786","hpzmsi01.exe","3612","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{86ABAF46-1F4E-4b45-9E13-6246D83303F3}","SUCCESS","Desired Access: All Access" "18:44:06.6341046","hpzmsi01.exe","3612","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{9716D554-3FBD-4DFD-8AE0-424EFD722D74}","SUCCESS","Desired Access: All Access" "18:44:06.6397145","hpzmsi01.exe","3612","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{B0564E46-594F-4E69-AEF9-AEE9C73050B8}","SUCCESS","Desired Access: All Access" "18:44:07.5437556","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:07.5439344","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165633" "18:44:07.6482516","hpqtra08.exe","3704","RegCreateKey","HKCR\CLSID\{68961B23-E3E2-4D7C-9072-6363436C1B25}\ClassData","SUCCESS","Desired Access: All Access" "18:44:07.6513375","hpqtra08.exe","3704","RegSetValue","HKCR\CLSID\{68961B23-E3E2-4D7C-9072-6363436C1B25}\ClassData\DefMfg","SUCCESS","Type: REG_SZ, Length: 32, Data: Hewlett-Packard" "18:44:07.6523555","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\CtxMgr\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:44:07.6719211","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:07.6720133","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165634" "18:44:07.6927701","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:07.6928483","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165635" "18:44:07.7088772","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:07.7089585","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165636" "18:44:07.7104905","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","NAME NOT FOUND","Desired Access: Read/Write" "18:44:07.7105564","hpqtra08.exe","3704","RegCreateKey","HKCU\Software","SUCCESS","Desired Access: Maximum Allowed" "18:44:07.7105852","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard","SUCCESS","Desired Access: Maximum Allowed" "18:44:07.7107252","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Maximum Allowed" "18:44:07.7155085","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr","SUCCESS","Desired Access: Maximum Allowed" "18:44:07.7436567","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:44:07.7445767","hpqtra08.exe","3704","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:44:07.7460325","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:44:07.7460733","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:44:07.7492812","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:44:07.7552632","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:44:07.8094905","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:07.8095791","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage\TrayApp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165633" "18:44:07.8517305","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:07.8519482","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage\TrayApp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165634" "18:44:08.9073099","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:08.9074105","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage\TrayApp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165635" "18:44:08.9322220","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:08.9323332","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage\TrayApp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165636" "18:44:08.9496813","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:08.9497628","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165637" "18:44:08.9948457","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:08.9953683","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165638" "18:44:09.0147647","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:09.0148527","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165639" "18:44:09.0156843","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:44:09.0157290","hpqtra08.exe","3704","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:44:09.0159288","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:44:09.0160313","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:44:09.0161171","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:44:09.0310494","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:09.0311346","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165640" "18:44:09.0378033","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:44:09.1007518","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:09.1008323","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage\TrayApp_Objs","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165633" "18:44:09.2017303","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:09.2018172","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage\TrayApp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165637" "18:44:09.2679119","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:09.2679935","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage\TrayApp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165638" "18:44:09.3672949","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:09.3673765","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage\TrayApp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165640" "18:44:09.4375162","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:09.4376553","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage\TrayApp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165641" "18:44:14.3912055","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6883F1BCF9EABF643852B67081892958\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:14.3913075","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6883F1BCF9EAbf643852B67081892958\Usage\TrayAppPlugIn","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165633" "18:44:14.4456840","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6883F1BCF9EABF643852B67081892958\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:14.4457747","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6883F1BCF9EAbf643852B67081892958\Usage\TrayAppPlugIn","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165634" "18:44:14.8502700","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:14.8503664","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage\TrayApp_Objs","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165634" "18:44:14.8742387","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:14.8743340","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage\TrayApp_Objs","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165635" "18:44:14.9361150","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6883F1BCF9EABF643852B67081892958\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:14.9362061","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6883F1BCF9EAbf643852B67081892958\Usage\TrayAppPlugIn","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165635" "18:44:15.3252642","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:15.3573680","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage\TrayApp_Objs","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165636" "18:44:15.5782340","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6892BBED0B5182D459AFC569A6935698\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:15.5783402","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6892BBED0B5182D459AFC569A6935698\Usage\RedboxMM","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165633" "18:44:15.8598855","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:15.8599766","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage\TrayApp_Objs","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165637" "18:44:18.1700277","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:18.1701336","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165641" "18:44:18.1899875","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:18.1901853","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage\TrayApp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165643" "18:44:18.2075797","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:18.2076559","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165642" "18:44:18.2450210","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:18.2451073","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165643" "18:44:18.2627107","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:18.2636823","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165644" "18:44:18.2646679","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:44:18.2647439","hpqtra08.exe","3704","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:44:18.2649392","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:44:18.2649696","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:44:18.2650624","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:44:18.2707461","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:44:18.2774953","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:44:18.2775704","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165645" "18:44:18.2797936","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:44:18.2798422","hpqtra08.exe","3704","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:44:18.2800358","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:44:18.2800671","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:44:18.2801341","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:44:18.2854502","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:44:18.2987195","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:44:18.2987756","hpqtra08.exe","3704","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:44:18.2990634","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:44:18.2990972","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:44:18.2991726","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:44:18.3042802","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:47:24.7799658","HPBOID.EXE","2528","RegCreateKey","HKCR","SUCCESS","Desired Access: Maximum Allowed" "18:47:24.7833140","HPBOID.EXE","2528","RegCreateKey","HKCR\AppID\{3B05F114-4087-4557-8952-AAF023709EB0}","SUCCESS","Desired Access: All Access" "18:47:24.8140283","HPBOID.EXE","2528","RegSetValue","HKCR\AppID\{3B05F114-4087-4557-8952-AAF023709EB0}\(Default)","SUCCESS","Type: REG_SZ, Length: 34, Data: HP Status Server" "18:47:24.8154656","HPBOID.EXE","2528","RegSetValue","HKCR\AppID\{3B05F114-4087-4557-8952-AAF023709EB0}\LaunchPermission","SUCCESS","Type: REG_BINARY, Length: 276, Data: 01 00 04 80 DC 00 00 00 F8 00 00 00 00 00 00 00" "18:47:24.8166135","HPBOID.EXE","2528","RegCreateKey","HKCR\AppID\HPboid.EXE","SUCCESS","Desired Access: All Access" "18:47:24.8676211","HPBOID.EXE","2528","RegSetValue","HKCR\AppID\HPboid.EXE\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {3B05F114-4087-4557-8952-AAF023709EB0}" "18:47:24.8683885","HPBOID.EXE","2528","RegDeleteValue","HKCR\AppID\{3B05F114-4087-4557-8952-AAF023709EB0}\LocalService","NAME NOT FOUND","" "18:47:24.8684223","HPBOID.EXE","2528","RegSetValue","HKCR\AppID\{3B05F114-4087-4557-8952-AAF023709EB0}\LocalService","SUCCESS","Type: REG_SZ, Length: 34, Data: HP Status Server" "18:47:24.8688922","HPBOID.EXE","2528","RegSetValue","HKCR\AppID\{3B05F114-4087-4557-8952-AAF023709EB0}\ServiceParameters","SUCCESS","Type: REG_SZ, Length: 18, Data: -Service" "18:47:24.9929921","HPBOID.EXE","2528","RegCreateKey","HKCR\HPStatusServer.HPBOID.1","SUCCESS","Desired Access: All Access" "18:47:25.0889238","HPBOID.EXE","2528","RegSetValue","HKCR\HPStatusServer.HPBOID.1\(Default)","SUCCESS","Type: REG_SZ, Length: 26, Data: HPBOID Class" "18:47:25.0903145","HPBOID.EXE","2528","RegCreateKey","HKCR\HPStatusServer.HPBOID.1\CLSID","SUCCESS","Desired Access: All Access" "18:47:25.0906911","HPBOID.EXE","2528","RegSetValue","HKCR\HPStatusServer.HPBOID.1\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {D713F357-7920-4B91-9EB6-49054709EC7A}" "18:47:25.1135979","HPBOID.EXE","2528","RegCreateKey","HKCR\HPStatusServer.HPBOID","SUCCESS","Desired Access: All Access" "18:47:25.1139706","HPBOID.EXE","2528","RegSetValue","HKCR\HPStatusServer.HPBOID\(Default)","SUCCESS","Type: REG_SZ, Length: 26, Data: HPBOID Class" "18:47:25.1143458","HPBOID.EXE","2528","RegCreateKey","HKCR\HPStatusServer.HPBOID\CLSID","SUCCESS","Desired Access: All Access" "18:47:25.1147237","HPBOID.EXE","2528","RegSetValue","HKCR\HPStatusServer.HPBOID\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {D713F357-7920-4B91-9EB6-49054709EC7A}" "18:47:25.1151366","HPBOID.EXE","2528","RegCreateKey","HKCR\CLSID\{D713F357-7920-4B91-9EB6-49054709EC7A}","SUCCESS","Desired Access: All Access" "18:47:25.1510708","HPBOID.EXE","2528","RegSetValue","HKCR\CLSID\{D713F357-7920-4B91-9EB6-49054709EC7A}\(Default)","SUCCESS","Type: REG_SZ, Length: 26, Data: HPBOID Class" "18:47:25.1516181","HPBOID.EXE","2528","RegCreateKey","HKCR\CLSID\{D713F357-7920-4B91-9EB6-49054709EC7A}\ProgID","SUCCESS","Desired Access: All Access" "18:47:25.1519159","HPBOID.EXE","2528","RegSetValue","HKCR\CLSID\{D713F357-7920-4B91-9EB6-49054709EC7A}\ProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 48, Data: HPStatusServer.HPBOID.1" "18:47:25.1522137","HPBOID.EXE","2528","RegCreateKey","HKCR\CLSID\{D713F357-7920-4B91-9EB6-49054709EC7A}\VersionIndependentProgID","SUCCESS","Desired Access: All Access" "18:47:25.1527710","HPBOID.EXE","2528","RegSetValue","HKCR\CLSID\{D713F357-7920-4B91-9EB6-49054709EC7A}\VersionIndependentProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 44, Data: HPStatusServer.HPBOID" "18:47:25.1530174","HPBOID.EXE","2528","RegSetValue","HKCR\CLSID\{D713F357-7920-4B91-9EB6-49054709EC7A}\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {3B05F114-4087-4557-8952-AAF023709EB0}" "18:47:25.1532800","HPBOID.EXE","2528","RegCreateKey","HKCR\CLSID\{D713F357-7920-4B91-9EB6-49054709EC7A}\LocalServer32","SUCCESS","Desired Access: All Access" "18:47:25.1541095","HPBOID.EXE","2528","RegSetValue","HKCR\CLSID\{D713F357-7920-4B91-9EB6-49054709EC7A}\LocalServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 108, Data: C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPBOID.EXE" "18:47:25.1779689","HPBOID.EXE","2528","RegCreateKey","HKCR\TypeLib\{06333F23-D064-4A34-B2DE-C30630C0B567}","SUCCESS","Desired Access: Maximum Allowed" "18:47:25.1856551","HPBOID.EXE","2528","RegCreateKey","HKCR\TypeLib\{06333F23-D064-4A34-B2DE-C30630C0B567}\1.0","SUCCESS","Desired Access: Maximum Allowed" "18:47:25.1862577","HPBOID.EXE","2528","RegSetValue","HKCR\TypeLib\{06333F23-D064-4A34-B2DE-C30630C0B567}\1.0\(Default)","SUCCESS","Type: REG_SZ, Length: 68, Data: HP Status Server 1.0 Type Library" "18:47:25.1865896","HPBOID.EXE","2528","RegCreateKey","HKCR\TypeLib\{06333F23-D064-4A34-B2DE-C30630C0B567}\1.0\FLAGS","SUCCESS","Desired Access: Maximum Allowed" "18:47:25.1868519","HPBOID.EXE","2528","RegSetValue","HKCR\TypeLib\{06333F23-D064-4A34-B2DE-C30630C0B567}\1.0\FLAGS\(Default)","SUCCESS","Type: REG_SZ, Length: 4, Data: 0" "18:47:25.1871852","HPBOID.EXE","2528","RegCreateKey","HKCR\TypeLib\{06333F23-D064-4A34-B2DE-C30630C0B567}\1.0\0","SUCCESS","Desired Access: Maximum Allowed" "18:47:25.1877299","HPBOID.EXE","2528","RegCreateKey","HKCR\TypeLib\{06333F23-D064-4A34-B2DE-C30630C0B567}\1.0\0\win32","SUCCESS","Desired Access: Maximum Allowed" "18:47:25.1879925","HPBOID.EXE","2528","RegSetValue","HKCR\TypeLib\{06333F23-D064-4A34-B2DE-C30630C0B567}\1.0\0\win32\(Default)","SUCCESS","Type: REG_SZ, Length: 108, Data: C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPBOID.EXE" "18:47:25.1882596","HPBOID.EXE","2528","RegCreateKey","HKCR\TypeLib\{06333F23-D064-4A34-B2DE-C30630C0B567}\1.0\HELPDIR","SUCCESS","Desired Access: Maximum Allowed" "18:47:25.1887192","HPBOID.EXE","2528","RegSetValue","HKCR\TypeLib\{06333F23-D064-4A34-B2DE-C30630C0B567}\1.0\HELPDIR\(Default)","SUCCESS","Type: REG_SZ, Length: 88, Data: C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\" "18:47:25.6813178","HPBPRO.EXE","2464","RegCreateKey","HKCR","SUCCESS","Desired Access: Maximum Allowed" "18:47:25.6912523","HPBPRO.EXE","2464","RegCreateKey","HKCR\AppID\{55F3F296-4775-4AE9-B0AA-52393842EF3C}","SUCCESS","Desired Access: All Access" "18:47:25.7206502","HPBPRO.EXE","2464","RegSetValue","HKCR\AppID\{55F3F296-4775-4AE9-B0AA-52393842EF3C}\(Default)","SUCCESS","Type: REG_SZ, Length: 34, Data: HP Port Resolver" "18:47:25.7212355","HPBPRO.EXE","2464","RegSetValue","HKCR\AppID\{55F3F296-4775-4AE9-B0AA-52393842EF3C}\LaunchPermission","SUCCESS","Type: REG_BINARY, Length: 276, Data: 01 00 04 80 DC 00 00 00 F8 00 00 00 00 00 00 00" "18:47:25.7223736","HPBPRO.EXE","2464","RegCreateKey","HKCR\AppID\hpbpro.EXE","SUCCESS","Desired Access: All Access" "18:47:25.7228477","HPBPRO.EXE","2464","RegSetValue","HKCR\AppID\hpbpro.EXE\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {55F3F296-4775-4AE9-B0AA-52393842EF3C}" "18:47:25.7233120","HPBPRO.EXE","2464","RegDeleteValue","HKCR\AppID\{55F3F296-4775-4AE9-B0AA-52393842EF3C}\LocalService","NAME NOT FOUND","" "18:47:25.7233427","HPBPRO.EXE","2464","RegSetValue","HKCR\AppID\{55F3F296-4775-4AE9-B0AA-52393842EF3C}\LocalService","SUCCESS","Type: REG_SZ, Length: 34, Data: HP Port Resolver" "18:47:25.7235142","HPBPRO.EXE","2464","RegSetValue","HKCR\AppID\{55F3F296-4775-4AE9-B0AA-52393842EF3C}\ServiceParameters","SUCCESS","Type: REG_SZ, Length: 18, Data: -Service" "18:47:25.8295584","HPBPRO.EXE","2464","RegCreateKey","HKCR\HPPortResolver.hpbpro.1","SUCCESS","Desired Access: All Access" "18:47:25.8670143","HPBPRO.EXE","2464","RegSetValue","HKCR\HPPortResolver.hpbpro.1\(Default)","SUCCESS","Type: REG_SZ, Length: 44, Data: HP Port Resolve Class" "18:47:25.8673524","HPBPRO.EXE","2464","RegCreateKey","HKCR\HPPortResolver.hpbpro.1\CLSID","SUCCESS","Desired Access: All Access" "18:47:25.8676027","HPBPRO.EXE","2464","RegSetValue","HKCR\HPPortResolver.hpbpro.1\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {5A5AA0AA-1DEB-4683-96B0-B43301E83971}" "18:47:25.8680178","HPBPRO.EXE","2464","RegCreateKey","HKCR\HPPortResolver.hpbpro","SUCCESS","Desired Access: All Access" "18:47:25.8682743","HPBPRO.EXE","2464","RegSetValue","HKCR\HPPortResolver.hpbpro\(Default)","SUCCESS","Type: REG_SZ, Length: 44, Data: HP Port Resolve Class" "18:47:25.8684994","HPBPRO.EXE","2464","RegCreateKey","HKCR\HPPortResolver.hpbpro\CLSID","SUCCESS","Desired Access: All Access" "18:47:25.8687659","HPBPRO.EXE","2464","RegSetValue","HKCR\HPPortResolver.hpbpro\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {5A5AA0AA-1DEB-4683-96B0-B43301E83971}" "18:47:25.8692322","HPBPRO.EXE","2464","RegCreateKey","HKCR\CLSID\{5A5AA0AA-1DEB-4683-96B0-B43301E83971}","SUCCESS","Desired Access: All Access" "18:47:25.9232793","HPBPRO.EXE","2464","RegSetValue","HKCR\CLSID\{5A5AA0AA-1DEB-4683-96B0-B43301E83971}\(Default)","SUCCESS","Type: REG_SZ, Length: 44, Data: HP Port Resolve Class" "18:47:25.9237981","HPBPRO.EXE","2464","RegCreateKey","HKCR\CLSID\{5A5AA0AA-1DEB-4683-96B0-B43301E83971}\ProgID","SUCCESS","Desired Access: All Access" "18:47:25.9242023","HPBPRO.EXE","2464","RegSetValue","HKCR\CLSID\{5A5AA0AA-1DEB-4683-96B0-B43301E83971}\ProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 48, Data: HPPortResolver.hpbpro.1" "18:47:25.9245440","HPBPRO.EXE","2464","RegCreateKey","HKCR\CLSID\{5A5AA0AA-1DEB-4683-96B0-B43301E83971}\VersionIndependentProgID","SUCCESS","Desired Access: All Access" "18:47:25.9250572","HPBPRO.EXE","2464","RegSetValue","HKCR\CLSID\{5A5AA0AA-1DEB-4683-96B0-B43301E83971}\VersionIndependentProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 44, Data: HPPortResolver.hpbpro" "18:47:25.9253497","HPBPRO.EXE","2464","RegSetValue","HKCR\CLSID\{5A5AA0AA-1DEB-4683-96B0-B43301E83971}\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {55F3F296-4775-4AE9-B0AA-52393842EF3C}" "18:47:25.9257807","HPBPRO.EXE","2464","RegCreateKey","HKCR\CLSID\{5A5AA0AA-1DEB-4683-96B0-B43301E83971}\LocalServer32","SUCCESS","Desired Access: All Access" "18:47:25.9282774","HPBPRO.EXE","2464","RegSetValue","HKCR\CLSID\{5A5AA0AA-1DEB-4683-96B0-B43301E83971}\LocalServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 108, Data: C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPBPRO.EXE" "18:47:25.9741036","HPBPRO.EXE","2464","RegCreateKey","HKCR\TypeLib\{CA2E8A2E-EDEC-4A6C-A92E-79A23A814F25}","SUCCESS","Desired Access: Maximum Allowed" "18:47:26.0008389","HPBPRO.EXE","2464","RegCreateKey","HKCR\TypeLib\{CA2E8A2E-EDEC-4A6C-A92E-79A23A814F25}\1.0","SUCCESS","Desired Access: Maximum Allowed" "18:47:26.0013227","HPBPRO.EXE","2464","RegSetValue","HKCR\TypeLib\{CA2E8A2E-EDEC-4A6C-A92E-79A23A814F25}\1.0\(Default)","SUCCESS","Type: REG_SZ, Length: 60, Data: PortResolver 1.0 Type Library" "18:47:26.0016013","HPBPRO.EXE","2464","RegCreateKey","HKCR\TypeLib\{CA2E8A2E-EDEC-4A6C-A92E-79A23A814F25}\1.0\FLAGS","SUCCESS","Desired Access: Maximum Allowed" "18:47:26.0019264","HPBPRO.EXE","2464","RegSetValue","HKCR\TypeLib\{CA2E8A2E-EDEC-4A6C-A92E-79A23A814F25}\1.0\FLAGS\(Default)","SUCCESS","Type: REG_SZ, Length: 4, Data: 0" "18:47:26.0022390","HPBPRO.EXE","2464","RegCreateKey","HKCR\TypeLib\{CA2E8A2E-EDEC-4A6C-A92E-79A23A814F25}\1.0\0","SUCCESS","Desired Access: Maximum Allowed" "18:47:26.0027542","HPBPRO.EXE","2464","RegCreateKey","HKCR\TypeLib\{CA2E8A2E-EDEC-4A6C-A92E-79A23A814F25}\1.0\0\win32","SUCCESS","Desired Access: Maximum Allowed" "18:47:26.0030665","HPBPRO.EXE","2464","RegSetValue","HKCR\TypeLib\{CA2E8A2E-EDEC-4A6C-A92E-79A23A814F25}\1.0\0\win32\(Default)","SUCCESS","Type: REG_SZ, Length: 108, Data: C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPBPRO.EXE" "18:47:26.0033803","HPBPRO.EXE","2464","RegCreateKey","HKCR\TypeLib\{CA2E8A2E-EDEC-4A6C-A92E-79A23A814F25}\1.0\HELPDIR","SUCCESS","Desired Access: Maximum Allowed" "18:47:26.0038063","HPBPRO.EXE","2464","RegSetValue","HKCR\TypeLib\{CA2E8A2E-EDEC-4A6C-A92E-79A23A814F25}\1.0\HELPDIR\(Default)","SUCCESS","Type: REG_SZ, Length: 88, Data: C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\" "18:47:28.6964971","HPBOID.EXE","2688","RegCreateKey","HKCR","SUCCESS","Desired Access: Maximum Allowed" "18:47:28.9158524","HPBPRO.EXE","4068","RegCreateKey","HKCR","SUCCESS","Desired Access: Maximum Allowed" "18:47:30.4751248","HPBPRO.EXE","540","RegCreateKey","HKCR","SUCCESS","Desired Access: Maximum Allowed" "18:47:30.9145986","HPBOID.EXE","1264","RegCreateKey","HKCR","SUCCESS","Desired Access: Maximum Allowed" "18:47:31.0688953","HPBOID.EXE","1264","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols","SUCCESS","Desired Access: All Access" "18:47:31.0690012","HPBOID.EXE","1264","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols\HPZipm12.exe","SUCCESS","Desired Access: All Access" "18:47:31.0690897","HPBOID.EXE","1264","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols\HPZipm12.exe\RtlDebugLevel","SUCCESS","Type: REG_DWORD, Length: 4, Data: 3" "18:47:31.7225742","HPBOID.EXE","1264","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols","SUCCESS","Desired Access: All Access" "18:47:31.7226298","HPBOID.EXE","1264","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols\HPZipm12.exe","SUCCESS","Desired Access: All Access" "18:47:36.9733664","HPBOID.EXE","2876","RegCreateKey","HKCR","SUCCESS","Desired Access: Maximum Allowed" "18:47:36.9775999","HPBOID.EXE","2876","RegSetValue","HKCR\AppID\{3B05F114-4087-4557-8952-AAF023709EB0}\(Default)","SUCCESS","Type: REG_SZ, Length: 34, Data: HP Status Server" "18:47:36.9777974","HPBOID.EXE","2876","RegSetValue","HKCR\AppID\{3B05F114-4087-4557-8952-AAF023709EB0}\LaunchPermission","SUCCESS","Type: REG_BINARY, Length: 276, Data: 01 00 04 80 DC 00 00 00 F8 00 00 00 00 00 00 00" "18:47:36.9779435","HPBOID.EXE","2876","RegSetValue","HKCR\AppID\HPboid.EXE\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {3B05F114-4087-4557-8952-AAF023709EB0}" "18:47:36.9781360","HPBOID.EXE","2876","RegDeleteValue","HKCR\AppID\{3B05F114-4087-4557-8952-AAF023709EB0}\LocalService","SUCCESS","" "18:47:36.9856277","HPBOID.EXE","2876","RegSetValue","HKCR\AppID\{3B05F114-4087-4557-8952-AAF023709EB0}\LocalService","SUCCESS","Type: REG_SZ, Length: 34, Data: HP Status Server" "18:47:36.9861309","HPBOID.EXE","2876","RegSetValue","HKCR\AppID\{3B05F114-4087-4557-8952-AAF023709EB0}\ServiceParameters","SUCCESS","Type: REG_SZ, Length: 18, Data: -Service" "18:47:37.1317946","HPBOID.EXE","2876","RegSetValue","HKCR\HPStatusServer.HPBOID.1\(Default)","SUCCESS","Type: REG_SZ, Length: 26, Data: HPBOID Class" "18:47:37.1319061","HPBOID.EXE","2876","RegSetValue","HKCR\HPStatusServer.HPBOID.1\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {D713F357-7920-4B91-9EB6-49054709EC7A}" "18:47:37.1320678","HPBOID.EXE","2876","RegSetValue","HKCR\HPStatusServer.HPBOID\(Default)","SUCCESS","Type: REG_SZ, Length: 26, Data: HPBOID Class" "18:47:37.1321855","HPBOID.EXE","2876","RegSetValue","HKCR\HPStatusServer.HPBOID\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {D713F357-7920-4B91-9EB6-49054709EC7A}" "18:47:37.1325830","HPBOID.EXE","2876","RegDeleteKey","HKCR\CLSID\{D713F357-7920-4B91-9EB6-49054709EC7A}\LocalServer32","SUCCESS","" "18:47:37.1366369","HPBOID.EXE","2876","RegDeleteKey","HKCR\CLSID\{D713F357-7920-4B91-9EB6-49054709EC7A}\ProgID","SUCCESS","" "18:47:37.1369313","HPBOID.EXE","2876","RegDeleteKey","HKCR\CLSID\{D713F357-7920-4B91-9EB6-49054709EC7A}\VersionIndependentProgID","SUCCESS","" "18:47:37.1371445","HPBOID.EXE","2876","RegDeleteKey","HKCR\CLSID\{D713F357-7920-4B91-9EB6-49054709EC7A}","SUCCESS","" "18:47:37.1499260","HPBOID.EXE","2876","RegCreateKey","HKCR\CLSID\{D713F357-7920-4B91-9EB6-49054709EC7A}","SUCCESS","Desired Access: All Access" "18:47:37.1503498","HPBOID.EXE","2876","RegSetValue","HKCR\CLSID\{D713F357-7920-4B91-9EB6-49054709EC7A}\(Default)","SUCCESS","Type: REG_SZ, Length: 26, Data: HPBOID Class" "18:47:37.1509116","HPBOID.EXE","2876","RegCreateKey","HKCR\CLSID\{D713F357-7920-4B91-9EB6-49054709EC7A}\ProgID","SUCCESS","Desired Access: All Access" "18:47:37.1513323","HPBOID.EXE","2876","RegSetValue","HKCR\CLSID\{D713F357-7920-4B91-9EB6-49054709EC7A}\ProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 48, Data: HPStatusServer.HPBOID.1" "18:47:37.1517946","HPBOID.EXE","2876","RegCreateKey","HKCR\CLSID\{D713F357-7920-4B91-9EB6-49054709EC7A}\VersionIndependentProgID","SUCCESS","Desired Access: All Access" "18:47:37.1525121","HPBOID.EXE","2876","RegSetValue","HKCR\CLSID\{D713F357-7920-4B91-9EB6-49054709EC7A}\VersionIndependentProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 44, Data: HPStatusServer.HPBOID" "18:47:37.1528786","HPBOID.EXE","2876","RegSetValue","HKCR\CLSID\{D713F357-7920-4B91-9EB6-49054709EC7A}\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {3B05F114-4087-4557-8952-AAF023709EB0}" "18:47:37.1532594","HPBOID.EXE","2876","RegCreateKey","HKCR\CLSID\{D713F357-7920-4B91-9EB6-49054709EC7A}\LocalServer32","SUCCESS","Desired Access: All Access" "18:47:37.1542790","HPBOID.EXE","2876","RegSetValue","HKCR\CLSID\{D713F357-7920-4B91-9EB6-49054709EC7A}\LocalServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 108, Data: C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE" "18:47:37.1781419","HPBOID.EXE","2876","RegSetValue","HKCR\TypeLib\{06333F23-D064-4A34-B2DE-C30630C0B567}\1.0\0\win32\(Default)","SUCCESS","Type: REG_SZ, Length: 108, Data: C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE" "18:47:37.1783908","HPBOID.EXE","2876","RegSetValue","HKCR\TypeLib\{06333F23-D064-4A34-B2DE-C30630C0B567}\1.0\HELPDIR\(Default)","SUCCESS","Type: REG_SZ, Length: 88, Data: C:\WINDOWS\system32\spool\drivers\w32x86\3\" "18:47:37.7304470","HPBPRO.EXE","1216","RegCreateKey","HKCR","SUCCESS","Desired Access: Maximum Allowed" "18:47:37.7463185","HPBPRO.EXE","1216","RegSetValue","HKCR\AppID\{55F3F296-4775-4AE9-B0AA-52393842EF3C}\(Default)","SUCCESS","Type: REG_SZ, Length: 34, Data: HP Port Resolver" "18:47:37.7465160","HPBPRO.EXE","1216","RegSetValue","HKCR\AppID\{55F3F296-4775-4AE9-B0AA-52393842EF3C}\LaunchPermission","SUCCESS","Type: REG_BINARY, Length: 276, Data: 01 00 04 80 DC 00 00 00 F8 00 00 00 00 00 00 00" "18:47:37.7467362","HPBPRO.EXE","1216","RegSetValue","HKCR\AppID\hpbpro.EXE\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {55F3F296-4775-4AE9-B0AA-52393842EF3C}" "18:47:37.7469136","HPBPRO.EXE","1216","RegDeleteValue","HKCR\AppID\{55F3F296-4775-4AE9-B0AA-52393842EF3C}\LocalService","SUCCESS","" "18:47:37.7518338","HPBPRO.EXE","1216","RegSetValue","HKCR\AppID\{55F3F296-4775-4AE9-B0AA-52393842EF3C}\LocalService","SUCCESS","Type: REG_SZ, Length: 34, Data: HP Port Resolver" "18:47:37.7544103","HPBPRO.EXE","1216","RegSetValue","HKCR\AppID\{55F3F296-4775-4AE9-B0AA-52393842EF3C}\ServiceParameters","SUCCESS","Type: REG_SZ, Length: 18, Data: -Service" "18:47:37.8004458","HPBPRO.EXE","1216","RegSetValue","HKCR\HPPortResolver.hpbpro.1\(Default)","SUCCESS","Type: REG_SZ, Length: 44, Data: HP Port Resolve Class" "18:47:37.8005520","HPBPRO.EXE","1216","RegSetValue","HKCR\HPPortResolver.hpbpro.1\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {5A5AA0AA-1DEB-4683-96B0-B43301E83971}" "18:47:37.8007143","HPBPRO.EXE","1216","RegSetValue","HKCR\HPPortResolver.hpbpro\(Default)","SUCCESS","Type: REG_SZ, Length: 44, Data: HP Port Resolve Class" "18:47:37.8008162","HPBPRO.EXE","1216","RegSetValue","HKCR\HPPortResolver.hpbpro\CLSID\(Default)","SUCCESS","Type: REG_SZ, Length: 78, Data: {5A5AA0AA-1DEB-4683-96B0-B43301E83971}" "18:47:37.8011875","HPBPRO.EXE","1216","RegDeleteKey","HKCR\CLSID\{5A5AA0AA-1DEB-4683-96B0-B43301E83971}\LocalServer32","SUCCESS","" "18:47:37.8021639","HPBPRO.EXE","1216","RegDeleteKey","HKCR\CLSID\{5A5AA0AA-1DEB-4683-96B0-B43301E83971}\ProgID","SUCCESS","" "18:47:37.8027025","HPBPRO.EXE","1216","RegDeleteKey","HKCR\CLSID\{5A5AA0AA-1DEB-4683-96B0-B43301E83971}\VersionIndependentProgID","SUCCESS","" "18:47:37.8030609","HPBPRO.EXE","1216","RegDeleteKey","HKCR\CLSID\{5A5AA0AA-1DEB-4683-96B0-B43301E83971}","SUCCESS","" "18:47:37.8080395","HPBPRO.EXE","1216","RegCreateKey","HKCR\CLSID\{5A5AA0AA-1DEB-4683-96B0-B43301E83971}","SUCCESS","Desired Access: All Access" "18:47:37.9194249","HPBPRO.EXE","1216","RegSetValue","HKCR\CLSID\{5A5AA0AA-1DEB-4683-96B0-B43301E83971}\(Default)","SUCCESS","Type: REG_SZ, Length: 44, Data: HP Port Resolve Class" "18:47:37.9200627","HPBPRO.EXE","1216","RegCreateKey","HKCR\CLSID\{5A5AA0AA-1DEB-4683-96B0-B43301E83971}\ProgID","SUCCESS","Desired Access: All Access" "18:47:37.9204680","HPBPRO.EXE","1216","RegSetValue","HKCR\CLSID\{5A5AA0AA-1DEB-4683-96B0-B43301E83971}\ProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 48, Data: HPPortResolver.hpbpro.1" "18:47:37.9209351","HPBPRO.EXE","1216","RegCreateKey","HKCR\CLSID\{5A5AA0AA-1DEB-4683-96B0-B43301E83971}\VersionIndependentProgID","SUCCESS","Desired Access: All Access" "18:47:37.9217299","HPBPRO.EXE","1216","RegSetValue","HKCR\CLSID\{5A5AA0AA-1DEB-4683-96B0-B43301E83971}\VersionIndependentProgID\(Default)","SUCCESS","Type: REG_SZ, Length: 44, Data: HPPortResolver.hpbpro" "18:47:37.9221523","HPBPRO.EXE","1216","RegSetValue","HKCR\CLSID\{5A5AA0AA-1DEB-4683-96B0-B43301E83971}\AppID","SUCCESS","Type: REG_SZ, Length: 78, Data: {55F3F296-4775-4AE9-B0AA-52393842EF3C}" "18:47:37.9231491","HPBPRO.EXE","1216","RegCreateKey","HKCR\CLSID\{5A5AA0AA-1DEB-4683-96B0-B43301E83971}\LocalServer32","SUCCESS","Desired Access: All Access" "18:47:37.9238260","HPBPRO.EXE","1216","RegSetValue","HKCR\CLSID\{5A5AA0AA-1DEB-4683-96B0-B43301E83971}\LocalServer32\(Default)","SUCCESS","Type: REG_SZ, Length: 108, Data: C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE" "18:47:37.9437143","HPBPRO.EXE","1216","RegSetValue","HKCR\TypeLib\{CA2E8A2E-EDEC-4A6C-A92E-79A23A814F25}\1.0\0\win32\(Default)","SUCCESS","Type: REG_SZ, Length: 108, Data: C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE" "18:47:37.9439191","HPBPRO.EXE","1216","RegSetValue","HKCR\TypeLib\{CA2E8A2E-EDEC-4A6C-A92E-79A23A814F25}\1.0\HELPDIR\(Default)","SUCCESS","Type: REG_SZ, Length: 88, Data: C:\WINDOWS\system32\spool\drivers\w32x86\3\" "18:48:12.3869338","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:12.3871726","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165646" "18:48:12.4861039","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:12.4861913","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165647" "18:48:12.5044624","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:12.5046895","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165648" "18:48:12.5055332","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:48:12.5055902","hpqtra08.exe","3704","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:48:12.5058369","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:48:12.5058695","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:48:12.5059444","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:48:12.5228424","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:12.5229206","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165649" "18:48:12.5403468","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:48:12.9322422","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:12.9323877","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165650" "18:48:12.9493480","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:12.9494307","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165651" "18:48:12.9542329","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:48:12.9543215","hpqtra08.exe","3704","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:48:12.9545777","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:48:12.9546137","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:48:12.9546900","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:48:12.9591836","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:48:30.1989367","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:30.1990828","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165652" "18:48:30.2022259","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxInfo\PlugIns","NAME NOT FOUND","Desired Access: Read/Write" "18:48:30.2022857","hpqtra08.exe","3704","RegCreateKey","HKLM\Software","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.2023212","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.2023907","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.2024645","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\CtxInfo","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.2077520","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\CtxInfo\PlugIns","SUCCESS","Desired Access: Read/Write" "18:48:30.2081429","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\CtxInfo\PlugIns\HP Deskjet 6940 series","SUCCESS","Type: REG_SZ, Length: 78, Data: {697F3101-0494-11d6-A2B0-0060B0FBD872}" "18:48:30.2085689","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read/Write" "18:48:30.2086385","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses\HP Deskjet 6940 series","SUCCESS","Type: REG_SZ, Length: 80, Data: Installed" "18:48:30.2874169","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings","NAME NOT FOUND","Desired Access: Read/Write" "18:48:30.2874560","hpqtra08.exe","3704","RegCreateKey","HKLM\Software","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.2877005","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.2877809","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.2878404","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.2881581","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read/Write" "18:48:30.2884955","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings\ProdFamily","SUCCESS","Type: REG_SZ, Length: 30, Data: 0,0,All-in-One" "18:48:30.2927656","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read/Write" "18:48:30.2928226","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings\ProdName","SUCCESS","Type: REG_SZ, Length: 24, Data: 0,0,deskjet" "18:48:30.2970517","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read/Write" "18:48:30.2971075","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings\ProdIconName","SUCCESS","Type: REG_SZ, Length: 24, Data: 0,0,deskjet" "18:48:30.3006172","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read/Write" "18:48:30.3006692","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings\ModelSeriesNum","SUCCESS","Type: REG_SZ, Length: 18, Data: 0,0,6940" "18:48:30.3046945","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read/Write" "18:48:30.3047470","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings\ModelSeriesStr","SUCCESS","Type: REG_SZ, Length: 78, Data: 0,0,$ProdName$ $ModelSeriesNum$ series" "18:48:30.3081609","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read/Write" "18:48:30.3082757","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings\ProdShortName","SUCCESS","Type: REG_SZ, Length: 62, Data: 0,0,$MfgAbbrevName$ $ProdName$" "18:48:30.3150391","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read/Write" "18:48:30.3151073","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings\ProdFullName","SUCCESS","Type: REG_SZ, Length: 74, Data: 0,0,$MfgAbbrevName$ $ModelSeriesStr$" "18:48:30.3187891","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read/Write" "18:48:30.3188388","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings\ProdIconFullName","SUCCESS","Type: REG_SZ, Length: 38, Data: 0,0,$ProdFullName$" "18:48:30.3226775","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read/Write" "18:48:30.3227298","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings\ProdModPrefix","SUCCESS","Type: REG_SZ, Length: 42, Data: 0,0,$MfgAbbrevName$o" "18:48:30.3349017","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read/Write" "18:48:30.3349797","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings\DefFriendlyName","SUCCESS","Type: REG_SZ, Length: 38, Data: 0,0,$ProdFullName$" "18:48:30.3392961","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read/Write" "18:48:30.3393528","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings\ModelTarget","SUCCESS","Type: REG_SZ, Length: 84, Data: 0,0,[Dd][Ee][Ss][Kk][Jj][Ee][Tt] 694[0-9]" "18:48:30.3700475","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read/Write" "18:48:30.3701188","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings\ProdClassDir","SUCCESS","Type: REG_SZ, Length: 62, Data: 0,0,$TargetDir$\$ProdFullName$" "18:48:30.3745777","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read/Write" "18:48:30.3746431","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings\ProdClassDataDir","SUCCESS","Type: REG_SZ, Length: 48, Data: 0,0,$ProdClassDir$\Data" "18:48:30.3790107","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read/Write" "18:48:30.3790730","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings\UninstallDir","SUCCESS","Type: REG_SZ, Length: 82, Data: 0,0,$TargetDir$\$ProdFullName$\Uninstall" "18:48:30.3831646","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read/Write" "18:48:30.3832168","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings\HPOJMain","SUCCESS","Type: REG_SZ, Length: 72, Data: 0,0,http://www.hp.com/go/all-in-one" "18:48:30.3886482","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read/Write" "18:48:30.3887161","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings\HPOJSupplies","SUCCESS","Type: REG_SZ, Length: 162, Data: 0,0,http://www.hp.com/cgi-bin/peripherals2/inkme.pl/HP%20OfficeJet%20G%20Series." "18:48:30.3928306","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read/Write" "18:48:30.3928839","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings\TourDir","SUCCESS","Type: REG_SZ, Length: 48, Data: 0,0,$ProdClassDir$\Tour" "18:48:30.4047047","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read/Write" "18:48:30.4047835","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings\CUERoot","SUCCESS","Type: REG_SZ, Length: 68, Data: 0,0,$MfgFullName$\Digital Imaging" "18:48:30.4092198","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read/Write" "18:48:30.4092760","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\Strings\MfgTarget","SUCCESS","Type: REG_SZ, Length: 26, Data: 0,0,[Hh][Pp]" "18:48:30.4189451","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CUE Settings\Defaults\hp Deskjet 6940 series\ScanButtonDefaults","NAME NOT FOUND","Desired Access: Write" "18:48:30.4189884","hpqtra08.exe","3704","RegCreateKey","HKLM\Software","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.4191697","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.4192479","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.4193088","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\CUE Settings","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.4199648","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\CUE Settings\Defaults","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.4203327","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\CUE Settings\Defaults\hp Deskjet 6940 series","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.4209104","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\CUE Settings\Defaults\hp Deskjet 6940 series\ScanButtonDefaults","SUCCESS","Desired Access: Write" "18:48:30.4213158","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\CUE Settings\Defaults\hp Deskjet 6940 series\ScanButtonDefaults\SWDestinationDefault","SUCCESS","Type: REG_SZ, Length: 22, Data: 0x00426E54" "18:48:30.4250808","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CUE Settings\Defaults\hp Deskjet 6940 series\ScanDocumentDefaults","SUCCESS","Desired Access: Write" "18:48:30.4291137","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\CUE Settings\Defaults\hp Deskjet 6940 series\ScanDocumentDefaults\SWAutoCropDefault","SUCCESS","Type: REG_SZ, Length: 4, Data: 0" "18:48:30.4332706","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CUE Settings\Defaults\hp Deskjet 6940 series\ScanPictureDefaults","SUCCESS","Desired Access: Write" "18:48:30.4338808","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\CUE Settings\Defaults\hp Deskjet 6940 series\ScanPictureDefaults\SWAutoCropDefault","SUCCESS","Type: REG_SZ, Length: 4, Data: 1" "18:48:30.4463109","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CUE Settings\Defaults\hp Deskjet 6940 series\ScanPreferencesDefaults","SUCCESS","Desired Access: Write" "18:48:30.4467888","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\CUE Settings\Defaults\hp Deskjet 6940 series\ScanPreferencesDefaults\SWAutoStraightenDefault","SUCCESS","Type: REG_SZ, Length: 4, Data: 1" "18:48:30.4550217","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CUE Settings\Defaults\hp Deskjet 6940 series\ScanPreferencesDefaults","SUCCESS","Desired Access: Write" "18:48:30.4550952","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\CUE Settings\Defaults\hp Deskjet 6940 series\ScanPreferencesDefaults\SWAutoExposeDefault","SUCCESS","Type: REG_SZ, Length: 4, Data: 0" "18:48:30.5003077","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CUE Settings\Defaults\hp Deskjet 6940 series\ScanPreferencesDefaults","SUCCESS","Desired Access: Write" "18:48:30.5003859","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\CUE Settings\Defaults\hp Deskjet 6940 series\ScanPreferencesDefaults\SWAdjustColorDefault","SUCCESS","Type: REG_SZ, Length: 4, Data: 0" "18:48:30.5288652","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CUE Settings\Defaults\hp Deskjet 6940 series\ScanPreferencesDefaults","SUCCESS","Desired Access: Write" "18:48:30.5289437","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\CUE Settings\Defaults\hp Deskjet 6940 series\ScanPreferencesDefaults\SWMaxPixelDepthDefault","SUCCESS","Type: REG_SZ, Length: 4, Data: 0" "18:48:30.5330029","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CUE Settings\Defaults\hp Deskjet 6940 series\ScanPreferencesDefaults","SUCCESS","Desired Access: Write" "18:48:30.5330635","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\CUE Settings\Defaults\hp Deskjet 6940 series\ScanPreferencesDefaults\SWBestQualityAPFDefault","SUCCESS","Type: REG_SZ, Length: 4, Data: 1" "18:48:30.5334675","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series","SUCCESS","Desired Access: Write" "18:48:30.5335018","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\InstallIndex","SUCCESS","Type: REG_SZ, Length: 4, Data: 1" "18:48:30.5483755","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series","SUCCESS","Desired Access: Write" "18:48:30.5484409","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\BaselineDataFileName","SUCCESS","Type: REG_SZ, Length: 156, Data: C:\Program Files\HP\Digital Imaging\hp Deskjet 6940 series\data\hpfdj6940.ini" "18:48:30.5711276","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:30.5712114","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165653" "18:48:30.5739810","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509","NAME NOT FOUND","Desired Access: Write" "18:48:30.5740112","hpqtra08.exe","3704","RegCreateKey","HKLM\Software","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.5740433","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.5741003","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.5741972","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.5742545","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.5748300","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509","SUCCESS","Desired Access: Write" "18:48:30.5750772","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\InstallIndex","SUCCESS","Type: REG_SZ, Length: 4, Data: 2" "18:48:30.5762316","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509","SUCCESS","Desired Access: Write" "18:48:30.5762799","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\BaselineDataFileName","SUCCESS","Type: REG_SZ, Length: 156, Data: C:\Program Files\HP\Digital Imaging\hp Deskjet 6940 series\data\hpfdj6940.ini" "18:48:30.5846547","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Functions\Print","NAME NOT FOUND","Desired Access: Write" "18:48:30.5846983","hpqtra08.exe","3704","RegCreateKey","HKLM\Software","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.5847402","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.5848243","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.5848860","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.5849430","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.5850008","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.5851411","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Functions","SUCCESS","Desired Access: Maximum Allowed" "18:48:30.5862663","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Functions\Print","SUCCESS","Desired Access: Write" "18:48:30.5866480","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Functions\Print\FriendlyName","SUCCESS","Type: REG_SZ, Length: 46, Data: HP Deskjet 6940 series" "18:48:30.5869441","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Functions\Print","SUCCESS","Desired Access: Write" "18:48:30.5869879","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Functions\Print\Port","SUCCESS","Type: REG_SZ, Length: 14, Data: USB001" "18:48:30.5880602","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Functions\Print","SUCCESS","Desired Access: Write" "18:48:30.5881037","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Functions\Print\ProductClass","SUCCESS","Type: REG_SZ, Length: 46, Data: HP Deskjet 6940 series" "18:48:30.5883457","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Functions\Print","SUCCESS","Desired Access: Write" "18:48:30.5883856","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Functions\Print\DatFile","SUCCESS","Type: REG_SZ, Length: 138, Data: C:\Program Files\HP\Digital Imaging\data\DeviceDiscovery\hpfdd09.ini" "18:48:30.5889125","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Functions\Print","SUCCESS","Desired Access: Write" "18:48:30.5889633","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Functions\Print\bNetworked","SUCCESS","Type: REG_SZ, Length: 4, Data: 0" "18:48:30.5893279","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Functions\Print","SUCCESS","Desired Access: Write" "18:48:30.5893695","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Functions\Print\PortType","SUCCESS","Type: REG_SZ, Length: 4, Data: 2" "18:48:30.9991618","hpqtra08.exe","3704","RegSetValue","HKLM\System\CurrentControlSet\Enum\USB\Vid_03f0&Pid_8904\MY822CS0DM04Q9\Device Parameters\SoftwareCUEContextID","SUCCESS","Type: REG_SZ, Length: 102, Data: #Hewlett-Packard#HP Deskjet 6940 series#1227552509" "18:48:31.0017166","hpqtra08.exe","3704","RegSetValue","HKLM\System\CurrentControlSet\Enum\USB\Vid_03f0&Pid_8904\MY822CS0DM04Q9\Device Parameters\DDDevNodeColor","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "18:48:31.0173954","hpqtra08.exe","3704","RegSetValue","HKLM\System\CurrentControlSet\Enum\USB\Vid_03f0&Pid_8904&MI_00\7&20e5f2ab&0&0000\Device Parameters\SoftwareCUEContextID","SUCCESS","Type: REG_SZ, Length: 102, Data: #Hewlett-Packard#HP Deskjet 6940 series#1227552509" "18:48:31.0186330","hpqtra08.exe","3704","RegSetValue","HKLM\System\CurrentControlSet\Enum\USB\Vid_03f0&Pid_8904&MI_00\7&20e5f2ab&0&0000\Device Parameters\DDDevNodeColor","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "18:48:31.0311329","hpqtra08.exe","3704","RegSetValue","HKLM\System\CurrentControlSet\Enum\USBPRINT\HPDeskjet_6940_series\8&19a447ac&0&USB001\Device Parameters\SoftwareCUEContextID","SUCCESS","Type: REG_SZ, Length: 102, Data: #Hewlett-Packard#HP Deskjet 6940 series#1227552509" "18:48:31.0322568","hpqtra08.exe","3704","RegSetValue","HKLM\System\CurrentControlSet\Enum\USBPRINT\HPDeskjet_6940_series\8&19a447ac&0&USB001\Device Parameters\DDDevNodeColor","SUCCESS","Type: REG_DWORD, Length: 4, Data: 2" "18:48:31.0510391","hpqtra08.exe","3704","RegSetValue","HKLM\System\CurrentControlSet\Enum\USB\Vid_03f0&Pid_8904&MI_01\7&20e5f2ab&0&0001\Device Parameters\SoftwareCUEContextID","SUCCESS","Type: REG_SZ, Length: 102, Data: #Hewlett-Packard#HP Deskjet 6940 series#1227552509" "18:48:31.0517104","hpqtra08.exe","3704","RegSetValue","HKLM\System\CurrentControlSet\Enum\USB\Vid_03f0&Pid_8904&MI_01\7&20e5f2ab&0&0001\Device Parameters\DDDevNodeColor","SUCCESS","Type: REG_DWORD, Length: 4, Data: 3" "18:48:31.0635748","hpqtra08.exe","3704","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\SoftwareCUEContextID","SUCCESS","Type: REG_SZ, Length: 102, Data: #Hewlett-Packard#HP Deskjet 6940 series#1227552509" "18:48:31.0649062","hpqtra08.exe","3704","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\DDDevNodeColor","SUCCESS","Type: REG_DWORD, Length: 4, Data: 4" "18:48:31.0786242","hpqtra08.exe","3704","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4\Vid_03f0&Pid_8904&MI_01&DOT4&PRINT_HPZ\9&2c247e8f&0&0\Device Parameters\SoftwareCUEContextID","SUCCESS","Type: REG_SZ, Length: 102, Data: #Hewlett-Packard#HP Deskjet 6940 series#1227552509" "18:48:31.0793114","hpqtra08.exe","3704","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4\Vid_03f0&Pid_8904&MI_01&DOT4&PRINT_HPZ\9&2c247e8f&0&0\Device Parameters\DDDevNodeColor","SUCCESS","Type: REG_DWORD, Length: 4, Data: 5" "18:48:31.0901349","hpqtra08.exe","3704","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4PRT\Vid_03f0&Pid_8904&MI_01&DOT4&PRINT_HPZ\a&1d2ef47&0&1\Device Parameters\SoftwareCUEContextID","SUCCESS","Type: REG_SZ, Length: 102, Data: #Hewlett-Packard#HP Deskjet 6940 series#1227552509" "18:48:31.0908757","hpqtra08.exe","3704","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4PRT\Vid_03f0&Pid_8904&MI_01&DOT4&PRINT_HPZ\a&1d2ef47&0&1\Device Parameters\DDDevNodeColor","SUCCESS","Type: REG_DWORD, Length: 4, Data: 6" "18:48:31.1662219","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Query Value, Set Value" "18:48:31.1981067","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:31.1981877","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165654" "18:48:31.2205126","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:31.2205992","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165655" "18:48:31.2215479","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:48:31.2216021","hpqtra08.exe","3704","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:48:31.2218038","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:48:31.2218360","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:48:31.2219100","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:48:31.2278462","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:48:31.2284441","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series","SUCCESS","Desired Access: Write" "18:48:31.2284826","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\InstallIndex","SUCCESS","Type: REG_SZ, Length: 6, Data: 49" "18:48:31.2287047","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:48:31.2314201","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:48:31.2344063","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509","SUCCESS","Desired Access: Write" "18:48:31.2344476","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\InstallIndex","SUCCESS","Type: REG_SZ, Length: 6, Data: 50" "18:48:31.2346602","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:48:31.2818799","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Strings\ContextID","SUCCESS","Type: REG_SZ, Length: 102, Data: #Hewlett-Packard#HP Deskjet 6940 series#1227552509" "18:48:31.2843126","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Strings\InstDataDir","SUCCESS","Type: REG_SZ, Length: 46, Data: 0,0,$InstanceDir$\Data" "18:48:31.2877468","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Strings\InstanceDir","SUCCESS","Type: REG_SZ, Length: 64, Data: 0,0,$ProdClassDir$\$InstanceID$" "18:48:31.2946720","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Strings\InstanceID","SUCCESS","Type: REG_SZ, Length: 30, Data: 0,0,1227552509" "18:48:31.2974034","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Strings\PrtDrvName","SUCCESS","Type: REG_SZ, Length: 38, Data: 0,0,$FriendlyName$" "18:48:31.3058656","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Strings\FriendlyName","SUCCESS","Type: REG_SZ, Length: 46, Data: HP Deskjet 6940 series" "18:48:31.3401091","hpqtra08.exe","3704","RegSetValue","HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Device","SUCCESS","Type: REG_SZ, Length: 76, Data: HP Deskjet 6940 series,winspool,Ne00:" "18:48:34.4519607","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Functions\1284.4","SUCCESS","Desired Access: Write" "18:48:34.4526237","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Functions\1284.4\OIDRTLName","SUCCESS","Type: REG_SZ, Length: 26, Data: hpzipr12.dll" "18:48:34.4549902","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Functions\1284.4","SUCCESS","Desired Access: Write" "18:48:34.4550435","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Functions\1284.4\Dot4RTLName","SUCCESS","Type: REG_SZ, Length: 26, Data: hpzidr12.dll" "18:48:34.5008843","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:34.5010198","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165656" "18:48:34.5290107","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:34.5290976","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165657" "18:48:34.5521455","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:34.5522369","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165658" "18:48:34.5560639","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:48:34.5561111","hpqtra08.exe","3704","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:48:34.5563187","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:48:34.5563522","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:48:34.5564223","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:48:34.5833361","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:34.5834193","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165659" "18:48:34.5881806","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:48:34.6451462","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:34.6452255","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165660" "18:48:34.6465715","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series","SUCCESS","Desired Access: Write" "18:48:34.6466070","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\InstallIndex","SUCCESS","Type: REG_SZ, Length: 12, Data: 14644" "18:48:34.6467916","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:48:34.6506662","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:48:34.6522770","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509","SUCCESS","Desired Access: Write" "18:48:34.6523158","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\InstallIndex","SUCCESS","Type: REG_SZ, Length: 12, Data: 12341" "18:48:34.6525189","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:48:34.6541130","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509","SUCCESS","Desired Access: Write" "18:48:34.6541563","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\ConnectionType","SUCCESS","Type: REG_SZ, Length: 4, Data: 2" "18:48:34.6607987","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Functions\1284.4","SUCCESS","Desired Access: Write" "18:48:34.6608716","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Functions\1284.4\ConnectionType","SUCCESS","Type: REG_SZ, Length: 4, Data: 2" "18:48:34.6636449","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Functions\1284.4","SUCCESS","Desired Access: Write" "18:48:34.6637656","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Functions\1284.4\PortNum","SUCCESS","Type: REG_SZ, Length: 4, Data: 1" "18:48:34.9997586","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Functions\1284.4","SUCCESS","Desired Access: Write" "18:48:34.9998952","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Functions\1284.4\PortID","SUCCESS","Type: REG_SZ, Length: 18, Data: DOT4_001" "18:48:35.0077328","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:48:35.0077923","hpqtra08.exe","3704","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:48:35.0080194","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:48:35.0080515","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:48:35.0081222","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:48:35.0127295","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:48:35.0136623","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:48:35.0165520","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:48:35.0171655","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:48:35.0199189","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:48:35.0199695","hpqtra08.exe","3704","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:48:35.0202237","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:48:35.0202545","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:48:35.0203891","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:48:35.0249903","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:48:35.0255054","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:48:35.0286525","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:48:35.0355933","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:48:35.0376966","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:48:35.0378173","hpqtra08.exe","3704","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:48:35.0380402","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:48:35.0380715","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:48:35.0381442","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:48:35.0444159","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:48:35.0450453","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:48:35.0476672","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:48:35.0523700","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:48:35.3632944","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:35.3633897","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165661" "18:48:35.3679372","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:48:35.3679875","hpqtra08.exe","3704","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:48:35.3682266","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:48:35.3682576","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:48:35.3683294","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:48:35.3759776","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:48:35.3767165","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:48:35.3804882","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:48:35.3812970","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:48:35.5477676","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6892BBED0B5182D459AFC569A6935698\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:35.5478651","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6892BBED0B5182D459AFC569A6935698\Usage\RedboxMM","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165634" "18:48:35.9210826","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6883F1BCF9EABF643852B67081892958\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:35.9211768","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6883F1BCF9EAbf643852B67081892958\Usage\TrayAppPlugIn","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165636" "18:48:35.9325159","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:48:35.9325665","hpqtra08.exe","3704","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:48:35.9327783","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:48:35.9328098","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:48:35.9328819","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:48:35.9410385","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:48:35.9419442","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:48:35.9446194","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:48:35.9453237","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:48:36.2065784","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:36.2066625","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage\TrayApp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165644" "18:48:36.2523247","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:48:36.2523775","hpqtra08.exe","3704","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:48:36.2525941","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:48:36.2526253","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:48:36.2527980","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:48:36.2582112","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:48:36.2590362","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:48:36.2618268","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:48:36.2625029","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:48:36.2732612","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:48:36.2733844","hpqtra08.exe","3704","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:48:36.2738563","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:48:36.2738912","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:48:36.2739688","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:48:36.2789351","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:48:36.2846529","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:48:36.2873105","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:48:36.2881075","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:48:36.3011840","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:48:36.3012541","hpqtra08.exe","3704","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:48:36.3014863","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:48:36.3015173","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:48:36.3015899","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:48:36.3060400","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:48:36.3067280","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:48:36.3091769","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:48:36.3100321","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:48:38.4319182","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:38.4320495","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165662" "18:48:38.6805398","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:38.6806300","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165663" "18:48:38.6999286","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:38.7000138","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165664" "18:48:38.7030717","hpqSTE08.exe","4008","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:48:38.7031192","hpqSTE08.exe","4008","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:48:38.7033293","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:48:38.7033639","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:48:38.7035489","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:48:38.7081919","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:48:38.7089037","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:48:38.7115851","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:48:38.7288607","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:48:38.9515100","hpqSTE08.exe","4008","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:48:38.9515703","hpqSTE08.exe","4008","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:48:38.9517977","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:48:38.9518324","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:48:38.9519125","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:48:38.9567313","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:48:38.9573621","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:48:38.9600692","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:48:38.9643060","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:48:41.3504126","hpqSTE08.exe","4008","RegCreateKey","HKCU\SOFTWARE\Microsoft\Internet Explorer\Security\P3Global","SUCCESS","Desired Access: Read, Set Value" "18:48:41.3504872","hpqSTE08.exe","4008","RegCreateKey","HKCU\SOFTWARE\Microsoft\Internet Explorer\Security\P3Sites","SUCCESS","Desired Access: Read, Create Sub Key" "18:48:46.0891124","hpqSTE08.exe","4008","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:48:46.0900281","hpqSTE08.exe","4008","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:48:46.2630501","hpqSTE08.exe","4008","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:48:46.2631535","hpqSTE08.exe","4008","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:48:47.8386378","hpqSTE08.exe","4008","RegCreateKey","HKCU\Software\Microsoft\Internet Explorer\Extensions\CmdMapping","SUCCESS","Desired Access: Read/Write" "18:48:47.8394631","hpqSTE08.exe","4008","RegCreateKey","HKCU\Software\Microsoft\Internet Explorer\Extensions\CmdMapping","SUCCESS","Desired Access: Read/Write" "18:48:50.7771074","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:50.7772730","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165665" "18:48:50.9017003","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:50.9017869","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165666" "18:48:50.9193992","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:50.9194771","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165667" "18:48:50.9206002","hpqSTE08.exe","4008","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:48:50.9206468","hpqSTE08.exe","4008","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:48:50.9208346","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:48:50.9208645","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:48:50.9209326","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:48:50.9296754","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:48:50.9304059","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:48:50.9336834","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:48:50.9345620","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:48:51.7128701","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked","SUCCESS","Desired Access: Read" "18:48:51.7129629","hpqSTE08.exe","4008","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked","SUCCESS","Desired Access: Read" "18:48:51.7133507","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached","SUCCESS","Desired Access: Read" "18:48:51.7134236","hpqSTE08.exe","4008","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached","SUCCESS","Desired Access: Read/Write" "18:48:52.3690737","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:52.3691614","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusimp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165633" "18:48:52.4402696","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:52.4403556","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusimp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165634" "18:48:53.6188210","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:53.6189406","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusimp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165635" "18:48:53.6245153","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:53.6245927","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusimp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165636" "18:48:53.6289458","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:53.6290539","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusimp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165637" "18:48:53.6507944","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:53.6508799","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusimp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165638" "18:48:53.6796710","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:53.6797785","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage\TrayApp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165645" "18:48:53.8247039","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:53.8247835","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusimp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165639" "18:48:53.9118767","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:53.9119575","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165668" "18:48:53.9419549","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:53.9420331","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165669" "18:48:53.9638590","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:48:53.9639395","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165670" "18:48:53.9648114","hpqSTE08.exe","4008","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:48:53.9648539","hpqSTE08.exe","4008","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:48:53.9650407","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:48:53.9650704","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:48:53.9651388","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:48:53.9701730","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:48:53.9709331","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:48:53.9740170","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:48:53.9811207","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:48:58.1339533","hpzcdl01.exe","3792","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}","SUCCESS","Desired Access: All Access" "18:48:58.1665532","hpzcdl01.exe","3792","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}\SourceDir","SUCCESS","Type: REG_SZ, Length: 8, Data: D:\" "18:49:00.0817620","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\HPDJ Printing System Config\HP Deskjet 6940 series","SUCCESS","Desired Access: Write" "18:49:00.0818349","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\HPDJ Printing System Config\hp deskjet 6940 series\HPDJEnableStatusClient","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "18:49:00.0896141","hpqSTE08.exe","4008","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:49:00.0897524","hpqSTE08.exe","4008","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:49:00.0899698","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:49:00.0900024","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:49:00.0900809","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:49:00.1288898","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:49:00.1296935","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:49:00.1323684","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:49:00.1330967","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:49:00.2581489","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:00.2582302","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusexe","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165633" "18:49:00.4791631","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:00.4792469","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusexe","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165634" "18:49:00.5498986","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:00.5499916","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusexe","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165635" "18:49:07.5863286","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:07.5864298","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusexe","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165636" "18:49:10.4368591","hpqSTE08.exe","4008","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:49:10.4369247","hpqSTE08.exe","4008","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:49:10.4371480","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:49:10.4372485","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:49:10.4373281","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:49:10.4422318","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:49:10.4429157","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:49:10.4467263","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:49:10.4498630","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:49:10.6524932","hpqSTE08.exe","4008","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:49:10.6525491","hpqSTE08.exe","4008","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:49:10.6527670","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:49:10.6527997","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:49:10.6528768","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:49:10.6658572","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:49:10.6666511","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:49:10.6717144","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:49:10.6725195","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:49:10.7210025","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:10.7210899","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusexe","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165637" "18:49:11.1231491","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:11.1232402","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage\TrayApp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165646" "18:49:11.1767285","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:11.1768110","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusexe","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165638" "18:49:11.2156768","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:11.2157533","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusexe","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165639" "18:49:11.2538967","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:11.2539937","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusexe","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165640" "18:49:11.3133797","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:11.3134733","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusexe","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165641" "18:49:11.5024557","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:11.5025521","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusexe","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165642" "18:49:11.5422429","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:11.5424259","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusexe","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165643" "18:49:11.6271053","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:11.6271878","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusexe","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165644" "18:49:11.7004147","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:11.7005781","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusexe","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165645" "18:49:12.1339488","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:12.1340390","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusexe","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165646" "18:49:12.1670108","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:12.1670910","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusexe","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165647" "18:49:12.4528329","hpqSTE08.exe","4008","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:49:12.4528871","hpqSTE08.exe","4008","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:49:12.4530969","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:49:12.4531966","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:49:12.4532749","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:49:12.4578754","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:49:12.4632024","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:49:12.4670286","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:49:12.4679114","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:49:14.3766361","hpzmsi01.exe","1196","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{A064DA9D-1ED3-410e-A3BB-6CB317202F7B}","SUCCESS","Desired Access: All Access" "18:49:14.4202525","hpzmsi01.exe","1196","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{A064DA9D-1ED3-410e-A3BB-6CB317202F7B}\CDGuid","SUCCESS","Type: REG_SZ, Length: 78, Data: {7ADE9F27-A175-447F-A4B4-B05FA82735E1}" "18:49:14.4365021","hpzmsi01.exe","1196","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{A064DA9D-1ED3-410e-A3BB-6CB317202F7B}","SUCCESS","Desired Access: All Access" "18:49:14.4365582","hpzmsi01.exe","1196","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{A064DA9D-1ED3-410e-A3BB-6CB317202F7B}\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1006633156" "18:49:14.4568739","hpzmsi01.exe","1196","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{A064DA9D-1ED3-410e-A3BB-6CB317202F7B}\Version_STR","SUCCESS","Type: REG_SZ, Length: 14, Data: 60.0.1" "18:49:14.4580744","hpzmsi01.exe","1196","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{A064DA9D-1ED3-410e-A3BB-6CB317202F7B}\Filename","SUCCESS","Type: REG_SZ, Length: 188, Data: C:\Program Files\HP\Digital Imaging\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}\Product\dj6940.msi" "18:49:14.4598531","hpzmsi01.exe","1196","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{A064DA9D-1ED3-410e-A3BB-6CB317202F7B}\section","SUCCESS","Type: REG_SZ, Length: 18, Data: MSI.6940" "18:49:16.0836067","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509","SUCCESS","Desired Access: Write" "18:49:16.0836539","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\AvailableFunctions","SUCCESS","Type: REG_SZ, Length: 4, Data: 1" "18:49:19.6635996","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:19.6637343","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165671" "18:49:19.6967136","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:19.6970452","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165672" "18:49:19.8062829","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:19.8064239","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165673" "18:49:19.8173477","hpqSTE08.exe","4008","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:49:19.8174075","hpqSTE08.exe","4008","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:49:19.8177019","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:49:19.8177734","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:49:19.8178522","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:49:19.9297424","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:19.9298315","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165674" "18:49:19.9651472","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:19.9652279","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165675" "18:49:19.9706778","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:49:19.9881870","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:19.9882714","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165676" "18:49:20.0361185","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:49:20.0395242","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:49:20.0403330","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:49:21.8087094","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509","SUCCESS","Desired Access: Write" "18:49:21.8088256","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\InstanceIDCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 180, Data: C:\Program Files\HP\Digital Imaging\hp deskjet 6940 series\1227552509\Data\1227552509.ini" "18:49:23.5539251","hpqSTE08.exe","4008","RegCreateKey","HKLM\System\CurrentControlSet\Control\DeviceClasses","SUCCESS","Desired Access: Read" "18:49:23.7936597","hpqSTE08.exe","4008","RegCreateKey","HKLM\System\CurrentControlSet\Control\DeviceClasses","SUCCESS","Desired Access: Read" "18:49:23.8839346","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:23.8840268","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165677" "18:49:23.9003859","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:23.9004694","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165678" "18:49:24.1713494","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:24.1714315","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165679" "18:49:25.3675215","hpqSTE08.exe","4008","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols","SUCCESS","Desired Access: All Access" "18:49:25.6968907","hpqSTE08.exe","4008","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols\HPZipm12.exe","SUCCESS","Desired Access: All Access" "18:49:25.7692175","hpqSTE08.exe","4008","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols","SUCCESS","Desired Access: All Access" "18:49:25.7692782","hpqSTE08.exe","4008","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols\HPZipm12.exe","SUCCESS","Desired Access: All Access" "18:49:25.8709729","hpqSTE08.exe","4008","RegCreateKey","HKLM\System\CurrentControlSet\Control\DeviceClasses","SUCCESS","Desired Access: Read" "18:49:26.0603302","HPZipm12.exe","1716","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols","SUCCESS","Desired Access: All Access" "18:49:26.0603931","HPZipm12.exe","1716","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols\HPZipm12.exe","SUCCESS","Desired Access: All Access" "18:49:27.5834643","HPZipm12.exe","1716","RegCreateKey","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters","SUCCESS","Desired Access: Read/Write, Write DAC" "18:49:27.5839200","HPZipm12.exe","1716","RegCreateKey","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Timeout","SUCCESS","Desired Access: All Access" "18:49:27.6792952","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Timeout\InterByteTimeout","SUCCESS","Type: REG_DWORD, Length: 4, Data: 500" "18:49:27.6813812","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Timeout\StandardPacketTimeout","SUCCESS","Type: REG_DWORD, Length: 4, Data: 3000" "18:49:27.6820486","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Timeout\CreditTimeout","SUCCESS","Type: REG_DWORD, Length: 4, Data: 5000" "18:49:27.6913850","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Timeout\PingTimer","SUCCESS","Type: REG_DWORD, Length: 4, Data: 10000" "18:49:27.6923773","HPZipm12.exe","1716","RegCreateKey","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Policy","SUCCESS","Desired Access: All Access" "18:49:27.6939068","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Policy\CreditOnZeroLength","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "18:49:27.6941580","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Policy\LogStreamData","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "18:49:27.6946391","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Policy\PiggyBackCredit","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "18:49:27.6950640","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Policy\AskCreditAfterWrite","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "18:49:27.6953512","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Policy\CommandPacketTwoParts","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "18:49:27.7257508","HPZipm12.exe","1716","RegCreateKey","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters","SUCCESS","Desired Access: Read/Write, Write DAC" "18:49:27.7260257","HPZipm12.exe","1716","RegCreateKey","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services","SUCCESS","Desired Access: All Access" "18:49:27.7533714","HPZipm12.exe","1716","RegCreateKey","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\IEEE-1284-4-TRANSACTION","SUCCESS","Desired Access: All Access" "18:49:27.7666770","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\IEEE-1284-4-TRANSACTION\HostToPeriSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:27.7670511","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\IEEE-1284-4-TRANSACTION\PeriToHostSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:27.7677548","HPZipm12.exe","1716","RegCreateKey","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-MESSAGE","SUCCESS","Desired Access: All Access" "18:49:27.8035216","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-MESSAGE\HostToPeriSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:27.8051746","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-MESSAGE\PeriToHostSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:27.8062083","HPZipm12.exe","1716","RegCreateKey","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\PRINT","SUCCESS","Desired Access: All Access" "18:49:27.8065424","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\PRINT\HostToPeriSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:27.8072967","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\PRINT\PeriToHostSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:27.8394874","HPZipm12.exe","1716","RegCreateKey","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-RESERVED-2","SUCCESS","Desired Access: All Access" "18:49:27.8710126","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-RESERVED-2\HostToPeriSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:27.8740661","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-RESERVED-2\PeriToHostSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:27.8917306","HPZipm12.exe","1716","RegCreateKey","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-SCAN","SUCCESS","Desired Access: All Access" "18:49:27.8936926","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-SCAN\HostToPeriSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:27.8949737","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-SCAN\PeriToHostSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:27.9117675","HPZipm12.exe","1716","RegCreateKey","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\MIO-COMMAND-PROCESSOR","SUCCESS","Desired Access: All Access" "18:49:27.9537656","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\MIO-COMMAND-PROCESSOR\HostToPeriSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:27.9540497","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\MIO-COMMAND-PROCESSOR\PeriToHostSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:27.9840697","HPZipm12.exe","1716","RegCreateKey","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-ECHO","SUCCESS","Desired Access: All Access" "18:49:28.0087751","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-ECHO\HostToPeriSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:28.0151348","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-ECHO\PeriToHostSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:28.0405434","HPZipm12.exe","1716","RegCreateKey","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-FAX-SEND","SUCCESS","Desired Access: All Access" "18:49:28.0434041","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-FAX-SEND\HostToPeriSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:28.0466844","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-FAX-SEND\PeriToHostSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:28.0622145","HPZipm12.exe","1716","RegCreateKey","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-FAX-RECEIVE","SUCCESS","Desired Access: All Access" "18:49:28.0834047","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-FAX-RECEIVE\HostToPeriSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:28.0845322","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-FAX-RECEIVE\PeriToHostSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:28.1328333","HPZipm12.exe","1716","RegCreateKey","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-DIAGNOSTICS","SUCCESS","Desired Access: All Access" "18:49:28.1362430","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-DIAGNOSTICS\HostToPeriSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:28.1436375","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-DIAGNOSTICS\PeriToHostSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:28.1466697","HPZipm12.exe","1716","RegCreateKey","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-RESERVED","SUCCESS","Desired Access: All Access" "18:49:28.1492586","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-RESERVED\HostToPeriSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:28.1496326","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-RESERVED\PeriToHostSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:28.1499198","HPZipm12.exe","1716","RegCreateKey","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-IMAGE-DOWNLOAD","SUCCESS","Desired Access: All Access" "18:49:28.1501067","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-IMAGE-DOWNLOAD\HostToPeriSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:28.1502710","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-IMAGE-DOWNLOAD\PeriToHostSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:28.1505833","HPZipm12.exe","1716","RegCreateKey","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-HOST-DATA-STORE-UPLOAD","SUCCESS","Desired Access: All Access" "18:49:28.1508077","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-HOST-DATA-STORE-UPLOAD\HostToPeriSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:28.1510320","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-HOST-DATA-STORE-UPLOAD\PeriToHostSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:28.1885541","HPZipm12.exe","1716","RegCreateKey","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-HOST-DATA-STORE-DOWNLOAD","SUCCESS","Desired Access: All Access" "18:49:28.1913444","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-HOST-DATA-STORE-DOWNLOAD\HostToPeriSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:28.1934030","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-HOST-DATA-STORE-DOWNLOAD\PeriToHostSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:28.3261590","HPZipm12.exe","1716","RegCreateKey","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-CONFIGURATION-UPLOAD","SUCCESS","Desired Access: All Access" "18:49:28.3354632","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-CONFIGURATION-UPLOAD\HostToPeriSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:28.3380745","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-CONFIGURATION-UPLOAD\PeriToHostSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:28.3413402","HPZipm12.exe","1716","RegCreateKey","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-CONFIGURATION-DOWNLOAD","SUCCESS","Desired Access: All Access" "18:49:28.3437975","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-CONFIGURATION-DOWNLOAD\HostToPeriSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:28.3463892","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-CONFIGURATION-DOWNLOAD\PeriToHostSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:28.4324032","HPZipm12.exe","1716","RegCreateKey","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-PCL-COPY","SUCCESS","Desired Access: All Access" "18:49:28.4398254","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-PCL-COPY\HostToPeriSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:28.4426467","HPZipm12.exe","1716","RegSetValue","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services\HP-PCL-COPY\PeriToHostSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1024" "18:49:28.5776328","HPZipm12.exe","1716","RegCreateKey","HKLM\System\CurrentControlSet\Enum\DOT4USB\Vid_03f0&Pid_8904&MI_01&DOT4\8&1e0bb67&0&1\Device Parameters\Services","SUCCESS","Desired Access: All Access" "18:49:28.9017877","hpzcdl01.exe","1560","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}","SUCCESS","Desired Access: All Access" "18:49:30.4766024","hpzcdl01.exe","1560","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}\SourceDir","SUCCESS","Type: REG_SZ, Length: 8, Data: D:\" "18:49:30.9351470","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:30.9352350","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusimp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165640" "18:49:30.9767786","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:30.9768682","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusimp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165641" "18:49:37.5008046","hpqSTE08.exe","4008","RegCreateKey","HKLM\System\CurrentControlSet\Control\DeviceClasses","SUCCESS","Desired Access: Read" "18:49:39.9185843","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:39.9186709","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165680" "18:49:39.9353811","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:49:39.9354683","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165681" "18:49:42.3323338","hpqpprop.exe","2728","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:49:42.3325841","hpqpprop.exe","2728","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:49:42.3337180","hpqpprop.exe","400","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:49:42.3337728","hpqpprop.exe","400","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:49:42.3340069","hpqpprop.exe","776","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:49:42.3340505","hpqpprop.exe","776","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:49:42.3345103","hpqpprop.exe","2728","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:49:42.3345559","hpqpprop.exe","2728","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:49:42.3484794","hpqpprop.exe","400","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:49:42.3485998","hpqpprop.exe","400","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:49:42.3576865","hpqpprop.exe","776","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:49:42.3577502","hpqpprop.exe","776","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:49:44.4007092","hpqpprop.exe","2728","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked","SUCCESS","Desired Access: Read" "18:49:44.4007922","hpqpprop.exe","2728","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked","SUCCESS","Desired Access: Read" "18:49:44.4011783","hpqpprop.exe","2728","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached","SUCCESS","Desired Access: Read" "18:49:44.4012442","hpqpprop.exe","2728","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached","SUCCESS","Desired Access: Read/Write" "18:49:44.4030975","hpqpprop.exe","400","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked","SUCCESS","Desired Access: Read" "18:49:44.4031646","hpqpprop.exe","400","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked","SUCCESS","Desired Access: Read" "18:49:44.4033470","hpqpprop.exe","400","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached","SUCCESS","Desired Access: Read" "18:49:44.4036565","hpqpprop.exe","400","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached","SUCCESS","Desired Access: Read/Write" "18:49:44.4061471","hpqpprop.exe","776","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked","SUCCESS","Desired Access: Read" "18:49:44.4062189","hpqpprop.exe","776","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked","SUCCESS","Desired Access: Read" "18:49:44.4066092","hpqpprop.exe","776","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached","SUCCESS","Desired Access: Read" "18:49:44.4066723","hpqpprop.exe","776","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached","SUCCESS","Desired Access: Read/Write" "18:50:19.8334316","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:50:19.8335752","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165682" "18:50:20.4341400","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:50:20.4342244","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165683" "18:50:20.4593633","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:50:20.4594567","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165684" "18:50:20.4607943","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:50:20.4934166","hpqtra08.exe","3704","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:50:20.4937116","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:50:20.4937479","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:50:20.4938378","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:50:20.5412240","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:50:20.5413073","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165685" "18:50:20.5849631","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:50:20.6989963","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:50:20.6990835","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165686" "18:50:20.7490085","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:50:20.7539622","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:50:20.7547872","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509","SUCCESS","Desired Access: Write" "18:50:20.7548272","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\InstanceIDCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 180, Data: C:\Program Files\HP\Digital Imaging\hp deskjet 6940 series\1227552509\Data\1227552509.ini" "18:50:20.7549193","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:50:23.5704378","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:50:23.5705560","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusexe","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165648" "18:50:27.5148637","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:50:27.5150162","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165687" "18:50:27.5589877","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:50:27.5590514","hpqtra08.exe","3704","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:50:27.5592777","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:50:27.5593115","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:50:27.5593909","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:50:27.5735530","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:50:27.5773786","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:50:27.5808746","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:50:27.5817040","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509","SUCCESS","Desired Access: Write" "18:50:27.5817423","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\InstanceIDCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 180, Data: C:\Program Files\HP\Digital Imaging\hp deskjet 6940 series\1227552509\Data\1227552509.ini" "18:50:27.5818233","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:50:27.8595466","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:50:27.8596313","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusexe","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165649" "18:50:29.3936603","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols","SUCCESS","Desired Access: All Access" "18:50:29.3942028","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols\HPZipm12.exe","SUCCESS","Desired Access: All Access" "18:50:29.4320515","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols","SUCCESS","Desired Access: All Access" "18:50:29.4330910","hpqtra08.exe","3704","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols\HPZipm12.exe","SUCCESS","Desired Access: All Access" "18:50:29.5806779","hpqtra08.exe","3704","RegCreateKey","HKLM\System\CurrentControlSet\Control\DeviceClasses","SUCCESS","Desired Access: Read" "18:50:30.4875949","hpqtra08.exe","3704","RegCreateKey","HKLM\System\CurrentControlSet\Control\DeviceClasses","SUCCESS","Desired Access: Read" "18:50:30.9234966","hpqtra08.exe","3704","RegCreateKey","HKLM\System\CurrentControlSet\Control\DeviceClasses","SUCCESS","Desired Access: Read" "18:50:34.4999721","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6892BBED0B5182D459AFC569A6935698\Usage","SUCCESS","Desired Access: Read, Set Value" "18:50:34.5001291","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6892BBED0B5182D459AFC569A6935698\Usage\RedboxMM","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165635" "18:50:39.0676848","hprblog.exe","3220","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6892BBED0B5182D459AFC569A6935698\Usage","SUCCESS","Desired Access: Read, Set Value" "18:50:39.0677767","hprblog.exe","3220","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6892BBED0B5182D459AFC569A6935698\Usage\RedboxMM","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165639" "18:50:44.4596002","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Functions\RedBox","SUCCESS","Desired Access: Write" "18:50:44.4877075","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Functions\RedBox\LastSeqNum","SUCCESS","Type: REG_SZ, Length: 12, Data: 7.001" "18:50:44.4924701","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Functions\RedBox","SUCCESS","Desired Access: Write" "18:50:44.4925296","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Functions\RedBox\LastSeqNum","SUCCESS","Type: REG_SZ, Length: 12, Data: 7.002" "18:50:44.4931031","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Functions\RedBox","SUCCESS","Desired Access: Write" "18:50:44.4931509","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Functions\RedBox\LastSeqNum","SUCCESS","Type: REG_SZ, Length: 12, Data: 7.003" "18:50:44.4953246","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Functions\RedBox","SUCCESS","Desired Access: Write" "18:50:44.4954014","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Functions\RedBox\LastSeqNum","SUCCESS","Type: REG_SZ, Length: 12, Data: 7.004" "18:50:44.5017537","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Functions\RedBox","SUCCESS","Desired Access: Write" "18:50:44.5019137","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\Functions\RedBox\LastSeqNum","SUCCESS","Type: REG_SZ, Length: 12, Data: 7.005" "18:51:07.3470248","hpzmsi01.exe","2356","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{B13F1594-4872-4CB0-B8EA-52FA5C56E88B}","SUCCESS","Desired Access: All Access" "18:51:07.3489675","hpzmsi01.exe","2356","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{B13F1594-4872-4CB0-B8EA-52FA5C56E88B}\CDGuid","SUCCESS","Type: REG_SZ, Length: 78, Data: {7ADE9F27-A175-447F-A4B4-B05FA82735E1}" "18:51:07.3514410","hpzmsi01.exe","2356","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{B13F1594-4872-4CB0-B8EA-52FA5C56E88B}","SUCCESS","Desired Access: All Access" "18:51:07.3514938","hpzmsi01.exe","2356","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{B13F1594-4872-4CB0-B8EA-52FA5C56E88B}\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1006633156" "18:51:07.3607975","hpzmsi01.exe","2356","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{B13F1594-4872-4CB0-B8EA-52FA5C56E88B}\Version_STR","SUCCESS","Type: REG_SZ, Length: 14, Data: 60.0.1" "18:51:07.3610428","hpzmsi01.exe","2356","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{B13F1594-4872-4CB0-B8EA-52FA5C56E88B}\Filename","SUCCESS","Type: REG_SZ, Length: 198, Data: C:\Program Files\HP\Digital Imaging\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}\Product\LP6940_help.msi" "18:51:07.3615719","hpzmsi01.exe","2356","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{B13F1594-4872-4CB0-B8EA-52FA5C56E88B}\section","SUCCESS","Type: REG_SZ, Length: 32, Data: MSI.LP6940_help" "18:51:17.1957555","hpzcdl01.exe","1188","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}","SUCCESS","Desired Access: All Access" "18:51:17.2230431","hpzcdl01.exe","1188","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}\SourceDir","SUCCESS","Type: REG_SZ, Length: 8, Data: D:\" "18:51:25.0301426","hpzmsi01.exe","3080","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{8C5855BB-08C1-4E72-830D-00ECE43B7F98}","SUCCESS","Desired Access: All Access" "18:51:25.0315738","hpzmsi01.exe","3080","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{8C5855BB-08C1-4E72-830D-00ECE43B7F98}\CDGuid","SUCCESS","Type: REG_SZ, Length: 78, Data: {7ADE9F27-A175-447F-A4B4-B05FA82735E1}" "18:51:25.0339529","hpzmsi01.exe","3080","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\Install\{8C5855BB-08C1-4E72-830D-00ECE43B7F98}","SUCCESS","Desired Access: All Access" "18:51:25.0340098","hpzmsi01.exe","3080","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{8C5855BB-08C1-4E72-830D-00ECE43B7F98}\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1006633156" "18:51:25.0346147","hpzmsi01.exe","3080","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{8C5855BB-08C1-4E72-830D-00ECE43B7F98}\Version_STR","SUCCESS","Type: REG_SZ, Length: 14, Data: 60.0.1" "18:51:25.0349636","hpzmsi01.exe","3080","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{8C5855BB-08C1-4E72-830D-00ECE43B7F98}\Filename","SUCCESS","Type: REG_SZ, Length: 194, Data: C:\Program Files\HP\Digital Imaging\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}\Product\LP6940Trb.msi" "18:51:25.0354785","hpzmsi01.exe","3080","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\Install\{8C5855BB-08C1-4E72-830D-00ECE43B7F98}\section","SUCCESS","Type: REG_SZ, Length: 28, Data: MSI.LP6940Trb" "18:51:29.2200771","hpzshl01.exe","2132","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\HPDJ Printing System Config","SUCCESS","Desired Access: All Access" "18:51:29.2289355","hpzshl01.exe","2132","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\HPDJ Printing System Config\LastInstallkey","SUCCESS","Type: REG_SZ, Length: 26, Data: DeskJet 6940" "18:51:29.2621852","hpzshl01.exe","2132","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\HPDJ Printing System Config","SUCCESS","Desired Access: All Access" "18:51:29.2689165","hpzshl01.exe","2132","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\HPDJ Printing System Config\LastInstallkey","SUCCESS","Type: REG_SZ, Length: 26, Data: DeskJet 6940" "18:51:35.0038267","hposid01.exe","1204","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:51:35.0039320","hposid01.exe","1204","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165688" "18:51:35.2569566","hposid01.exe","1204","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:51:35.2571335","hposid01.exe","1204","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165689" "18:51:35.2823598","hposid01.exe","1204","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:51:35.2825238","hposid01.exe","1204","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165690" "18:51:35.2842028","hposid01.exe","1204","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:51:35.2843107","hposid01.exe","1204","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:51:35.2845758","hposid01.exe","1204","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:51:35.2846115","hposid01.exe","1204","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:51:35.2846881","hposid01.exe","1204","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:51:35.2896164","hposid01.exe","1204","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:51:35.3025524","hposid01.exe","1204","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:51:35.3074656","hposid01.exe","1204","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:51:35.3082939","hposid01.exe","1204","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509","SUCCESS","Desired Access: Write" "18:51:35.3083335","hposid01.exe","1204","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\InstanceIDCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 180, Data: C:\Program Files\HP\Digital Imaging\hp deskjet 6940 series\1227552509\Data\1227552509.ini" "18:51:35.3084403","hposid01.exe","1204","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:51:36.5752406","hposid01.exe","1204","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:51:36.5754870","hposid01.exe","1204","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusexe","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165650" "18:51:37.7845111","hposid01.exe","1204","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:51:37.7845826","hposid01.exe","1204","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:51:37.7848047","hposid01.exe","1204","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:51:37.7849832","hposid01.exe","1204","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:51:37.7850626","hposid01.exe","1204","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:51:37.7899746","hposid01.exe","1204","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:51:37.7907113","hposid01.exe","1204","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:51:37.7944104","hposid01.exe","1204","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:51:37.7951412","hposid01.exe","1204","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509","SUCCESS","Desired Access: Write" "18:51:37.7951840","hposid01.exe","1204","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\InstanceIDCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 180, Data: C:\Program Files\HP\Digital Imaging\hp deskjet 6940 series\1227552509\Data\1227552509.ini" "18:51:37.7952627","hposid01.exe","1204","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:51:38.0173994","hposid01.exe","1204","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols","SUCCESS","Desired Access: All Access" "18:51:38.0174709","hposid01.exe","1204","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols\HPZipm12.exe","SUCCESS","Desired Access: All Access" "18:51:38.0178550","hposid01.exe","1204","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols","SUCCESS","Desired Access: All Access" "18:51:38.0179036","hposid01.exe","1204","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols\HPZipm12.exe","SUCCESS","Desired Access: All Access" "18:51:38.0652113","hposid01.exe","1204","RegCreateKey","HKLM\System\CurrentControlSet\Control\DeviceClasses","SUCCESS","Desired Access: Read" "18:51:40.2024634","hpqWRG.exe","1624","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\WebReg","SUCCESS","Desired Access: Write" "18:51:40.2048165","hpqWRG.exe","1624","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\WebReg\Deskjet 6940 series","SUCCESS","Desired Access: Write" "18:51:40.2050523","hpqWRG.exe","1624","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\WebReg\Deskjet 6940 series\Product Name","SUCCESS","Type: REG_SZ, Length: 40, Data: Deskjet 6940 series" "18:51:40.2052598","hpqWRG.exe","1624","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\WebReg\Deskjet 6940 series\Model ID","SUCCESS","Type: REG_SZ, Length: 14, Data: X0000A" "18:51:40.2057884","hpqWRG.exe","1624","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\WebReg\Deskjet 6940 series\Serial Number","SUCCESS","Type: REG_SZ, Length: 30, Data: MY822CS0DM04Q9" "18:51:40.2059677","hpqWRG.exe","1624","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\WebReg\Deskjet 6940 series\Application ID","SUCCESS","Type: REG_SZ, Length: 8, Data: 303" "18:51:40.2063547","hpqWRG.exe","1624","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\WebReg\Deskjet 6940 series\Product Line","SUCCESS","Type: REG_SZ, Length: 6, Data: 5M" "18:51:41.7909382","hpqWRG.exe","1624","RegCreateKey","HKCU\SOFTWARE\Microsoft\Internet Explorer\Security\P3Global","SUCCESS","Desired Access: Read, Set Value" "18:51:41.7910035","hpqWRG.exe","1624","RegCreateKey","HKCU\SOFTWARE\Microsoft\Internet Explorer\Security\P3Sites","SUCCESS","Desired Access: Read, Create Sub Key" "18:51:42.8527955","hpqWRG.exe","1624","RegCreateKey","HKCU\Software\Microsoft\Internet Explorer\Extensions\CmdMapping","SUCCESS","Desired Access: Read/Write" "18:51:42.8655356","hpqWRG.exe","1624","RegCreateKey","HKCU\Software\Microsoft\Internet Explorer\Extensions\CmdMapping","SUCCESS","Desired Access: Read/Write" "18:51:46.2013054","hpqWRG.exe","1624","RegCreateKey","HKCU\SOFTWARE\Microsoft\Internet Explorer\Security\P3Global","SUCCESS","Desired Access: Read, Set Value" "18:51:46.2013789","hpqWRG.exe","1624","RegCreateKey","HKCU\SOFTWARE\Microsoft\Internet Explorer\Security\P3Sites","SUCCESS","Desired Access: Read, Create Sub Key" "18:51:50.1730560","hpqWRG.exe","1624","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:51:50.1736555","hpqWRG.exe","1624","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:51:50.1742919","hpqWRG.exe","1624","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:51:50.1743525","hpqWRG.exe","1624","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:51:50.3356669","hpqWRG.exe","1624","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked","SUCCESS","Desired Access: Read" "18:51:50.3361027","hpqWRG.exe","1624","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked","SUCCESS","Desired Access: Read" "18:51:50.3368654","hpqWRG.exe","1624","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached","SUCCESS","Desired Access: Read" "18:51:50.3369486","hpqWRG.exe","1624","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached","SUCCESS","Desired Access: Read/Write" "18:52:10.6552572","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:52:10.6553489","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165691" "18:52:10.6815483","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:52:10.6816290","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165692" "18:52:10.6984393","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:52:10.6986650","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165693" "18:52:10.6995335","hpqtra08.exe","3704","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:52:10.6995947","hpqtra08.exe","3704","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:52:10.6998506","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:52:10.6998878","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:52:10.6999632","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:52:10.7092080","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:52:10.7100120","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:52:10.7165245","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:52:10.7174900","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509","SUCCESS","Desired Access: Write" "18:52:10.7175305","hpqtra08.exe","3704","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\InstanceIDCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 180, Data: C:\Program Files\HP\Digital Imaging\hp deskjet 6940 series\1227552509\Data\1227552509.ini" "18:52:10.7176085","hpqtra08.exe","3704","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:52:26.5940618","hpqdirec.exe","2512","RegCreateKey","HKCU\Software\Microsoft\GDIPlus","SUCCESS","Desired Access: All Access" "18:52:26.7196604","hpqdirec.exe","2512","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:52:26.7197490","hpqdirec.exe","2512","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165694" "18:52:26.7850614","hpqdirec.exe","2512","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:52:26.7852302","hpqdirec.exe","2512","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165695" "18:52:26.8055478","hpqdirec.exe","2512","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:52:26.8056484","hpqdirec.exe","2512","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165696" "18:52:26.8072548","hpqdirec.exe","2512","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:52:26.8073120","hpqdirec.exe","2512","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:52:26.8075596","hpqdirec.exe","2512","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:52:26.8075950","hpqdirec.exe","2512","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:52:26.8076646","hpqdirec.exe","2512","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:52:26.8130379","hpqdirec.exe","2512","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:52:26.8139006","hpqdirec.exe","2512","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:52:26.8178709","hpqdirec.exe","2512","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:52:26.8186034","hpqdirec.exe","2512","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509","SUCCESS","Desired Access: Write" "18:52:26.8186531","hpqdirec.exe","2512","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\InstanceIDCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 180, Data: C:\Program Files\HP\Digital Imaging\hp deskjet 6940 series\1227552509\Data\1227552509.ini" "18:52:26.8187289","hpqdirec.exe","2512","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:52:26.8450417","hpqdirec.exe","2512","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:52:26.8451233","hpqdirec.exe","2512","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165697" "18:52:27.1954474","hpqdirec.exe","2512","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:52:27.1955105","hpqdirec.exe","2512","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:52:27.1960369","hpqdirec.exe","2512","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:52:27.1960838","hpqdirec.exe","2512","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:52:29.1151450","hpqdirec.exe","2512","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:52:29.1152291","hpqdirec.exe","2512","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\CRMCM","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165633" "18:52:29.1241811","hpqdirec.exe","2512","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:52:29.1243266","hpqdirec.exe","2512","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\CRMCM","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165634" "18:52:42.2516914","hpqdirec.exe","2512","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked","SUCCESS","Desired Access: Read" "18:52:42.2519641","hpqdirec.exe","2512","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked","SUCCESS","Desired Access: Read" "18:52:42.2522745","hpqdirec.exe","2512","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached","SUCCESS","Desired Access: Read" "18:52:42.2523739","hpqdirec.exe","2512","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached","SUCCESS","Desired Access: Read/Write" "18:52:43.8040412","hpqSTE08.exe","3396","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:52:43.8041239","hpqSTE08.exe","3396","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165698" "18:52:43.8459580","hpqSTE08.exe","3396","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:52:43.8460418","hpqSTE08.exe","3396","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165699" "18:52:43.8662452","hpqSTE08.exe","3396","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:52:43.8663274","hpqSTE08.exe","3396","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165700" "18:52:43.8696864","hpqSTE08.exe","3396","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read/Write" "18:52:43.8697334","hpqSTE08.exe","3396","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings\ImagesDir","SUCCESS","Type: REG_SZ, Length: 36, Data: 0,1,$My Pictures$" "18:52:43.8699259","hpqSTE08.exe","3396","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging","SUCCESS","Desired Access: Write" "18:52:43.8699577","hpqSTE08.exe","3396","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\MfgCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 46, Data: $TargetDir$\CtxMgr.ini" "18:52:43.8723608","hpqSTE08.exe","3396","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\Strings","SUCCESS","Desired Access: Read" "18:52:43.8785189","hpqSTE08.exe","3396","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\CtxMgr\ProductClasses","SUCCESS","Desired Access: Read" "18:52:43.8793223","hpqSTE08.exe","3396","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\Strings","SUCCESS","Desired Access: Read" "18:52:43.8827691","hpqSTE08.exe","3396","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances","SUCCESS","Desired Access: Read" "18:52:43.8834483","hpqSTE08.exe","3396","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509","SUCCESS","Desired Access: Write" "18:52:43.8834857","hpqSTE08.exe","3396","RegSetValue","HKLM\SOFTWARE\Hewlett-Packard\DigitalImaging\hp Deskjet 6940 series\DeviceInstances\1227552509\InstanceIDCtxInfoFile","SUCCESS","Type: REG_SZ, Length: 180, Data: C:\Program Files\HP\Digital Imaging\hp deskjet 6940 series\1227552509\Data\1227552509.ini" "18:52:43.8835910","hpqSTE08.exe","3396","RegCreateKey","HKLM\Software\Hewlett-Packard\DigitalImaging\HP Deskjet 6940 series\DeviceInstances\1227552509\Strings","SUCCESS","Desired Access: Read" "18:52:53.4429484","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage","SUCCESS","Desired Access: Read, Set Value" "18:52:53.4430727","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage\TrayApp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165647" "18:52:54.0209831","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage","SUCCESS","Desired Access: Read, Set Value" "18:52:54.0210677","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EBF5FB07093F1A4E984B8665E82056D\Usage\TrayApp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165648" "18:52:54.0340288","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:52:54.0341127","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165701" "18:52:54.4476356","hpqpprop.exe","2116","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:52:54.4477013","hpqpprop.exe","2116","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:52:54.4481899","hpqpprop.exe","2116","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:52:54.4482334","hpqpprop.exe","2116","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:52:54.5055765","hpqpprop.exe","2116","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked","SUCCESS","Desired Access: Read" "18:52:54.5056488","hpqpprop.exe","2116","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked","SUCCESS","Desired Access: Read" "18:52:54.5058651","hpqpprop.exe","2116","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached","SUCCESS","Desired Access: Read" "18:52:54.5059344","hpqpprop.exe","2116","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached","SUCCESS","Desired Access: Read/Write" "18:52:56.6331458","hpqtbx01.exe","3028","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols","SUCCESS","Desired Access: All Access" "18:52:56.6332774","hpqtbx01.exe","3028","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols\HPZipm12.exe","SUCCESS","Desired Access: All Access" "18:52:56.6352069","hpqtbx01.exe","3028","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols","SUCCESS","Desired Access: All Access" "18:52:56.6352519","hpqtbx01.exe","3028","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols\HPZipm12.exe","SUCCESS","Desired Access: All Access" "18:52:56.6589396","hpqtbx01.exe","3028","RegCreateKey","HKLM\System\CurrentControlSet\Control\DeviceClasses","SUCCESS","Desired Access: Read" "18:52:56.9005689","hpqtbx01.exe","3028","RegCreateKey","HKLM\System\CurrentControlSet\Control\DeviceClasses","SUCCESS","Desired Access: Read" "18:53:07.7014461","hpqtbx01.exe","3028","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols","SUCCESS","Desired Access: All Access" "18:53:07.7015154","hpqtbx01.exe","3028","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols\HPZipm12.exe","SUCCESS","Desired Access: All Access" "18:53:07.7074438","hpqtbx01.exe","3028","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols","SUCCESS","Desired Access: All Access" "18:53:07.7074943","hpqtbx01.exe","3028","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols\HPZipm12.exe","SUCCESS","Desired Access: All Access" "18:53:07.7087900","hpqtbx01.exe","3028","RegCreateKey","HKLM\System\CurrentControlSet\Control\DeviceClasses","SUCCESS","Desired Access: Read" "18:53:07.7143865","hpqtbx01.exe","3028","RegCreateKey","HKLM\System\CurrentControlSet\Control\DeviceClasses","SUCCESS","Desired Access: Read" "18:53:11.8530586","hpqtbx01.exe","3028","RegCreateKey","HKCU\Software\Hewlett-Packard\DEMFileData\HP Deskjet 6940 series","NAME NOT FOUND","Desired Access: Read" "18:53:11.8532765","hpqtbx01.exe","3028","RegCreateKey","HKCU\Software","SUCCESS","Desired Access: Maximum Allowed" "18:53:11.8533134","hpqtbx01.exe","3028","RegCreateKey","HKCU\Software\Hewlett-Packard","SUCCESS","Desired Access: Maximum Allowed" "18:53:11.8533827","hpqtbx01.exe","3028","RegCreateKey","HKCU\Software\Hewlett-Packard\DEMFileData","SUCCESS","Desired Access: Maximum Allowed" "18:53:11.8687299","hpqtbx01.exe","3028","RegCreateKey","HKCU\Software\Hewlett-Packard\DEMFileData\HP Deskjet 6940 series","SUCCESS","Desired Access: Read" "18:53:12.8366445","hpqtbx01.exe","3028","RegCreateKey","HKLM\Software\Hewlett-Packard\\HP Unidrv\Borderless Forms","SUCCESS","Desired Access: Query Value" "18:53:12.8368432","hpqtbx01.exe","3028","RegCreateKey","HKLM\Software\Hewlett-Packard\\HP Unidrv\Borderless Forms","SUCCESS","Desired Access: Query Value" "18:53:13.2790848","hpqtbx01.exe","3028","RegCreateKey","HKLM\Software\Hewlett-Packard\\HP Unidrv\Borderless Forms","SUCCESS","Desired Access: Query Value" "18:53:13.6037141","hpqtbx01.exe","3028","RegCreateKey","HKCU\Software\Hewlett-Packard\DEMFileData\HP Deskjet 6940 series","SUCCESS","Desired Access: Read" "18:53:13.6213879","hpqtbx01.exe","3028","RegCreateKey","HKCU\Software\Hewlett-Packard\DEMFileData\HP Deskjet 6940 series","SUCCESS","Desired Access: Read" "18:53:13.7525998","hpqtbx01.exe","3028","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:53:13.7526635","hpqtbx01.exe","3028","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:53:13.7531278","hpqtbx01.exe","3028","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:53:13.7531722","hpqtbx01.exe","3028","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:53:13.8336766","hpqtbx01.exe","3028","RegCreateKey","HKCU\Software\Hewlett-Packard\DEMFileData\HP Deskjet 6940 series","SUCCESS","Desired Access: Read" "18:53:13.8792039","hpqtbx01.exe","3028","RegCreateKey","HKCU\Software\Hewlett-Packard\b4e95958-8d86-428f-02b8-96f334e88e80","SUCCESS","Desired Access: All Access" "18:53:13.8799302","hpqtbx01.exe","3028","RegSetValue","HKCU\Software\Hewlett-Packard\b4e95958-8d86-428f-02b8-96f334e88e80\ShowJobStorageDlg","SUCCESS","Type: REG_BINARY, Length: 1, Data: 01" "18:53:22.7677162","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage","SUCCESS","Desired Access: Read, Set Value" "18:53:22.7683339","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2BD35EB42F1C1D449ABA6103ABF7A21F\Usage\ContextManager10","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165702" "18:53:24.1020378","hpqpprop.exe","3796","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:53:24.1020973","hpqpprop.exe","3796","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:53:24.1022783","hpqpprop.exe","256","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:53:24.1023219","hpqpprop.exe","256","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:53:24.1032594","hpqpprop.exe","3796","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:53:24.1033128","hpqpprop.exe","3796","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:53:24.1037492","hpqpprop.exe","256","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:53:24.1038341","hpqpprop.exe","256","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:53:24.1728524","hpqpprop.exe","256","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked","SUCCESS","Desired Access: Read" "18:53:24.1736418","hpqpprop.exe","3796","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked","SUCCESS","Desired Access: Read" "18:53:24.1959980","hpqpprop.exe","3796","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked","SUCCESS","Desired Access: Read" "18:53:24.1962307","hpqpprop.exe","256","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked","SUCCESS","Desired Access: Read" "18:53:24.2919882","hpqpprop.exe","256","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached","SUCCESS","Desired Access: Read" "18:53:24.2925265","hpqpprop.exe","256","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached","SUCCESS","Desired Access: Read/Write" "18:53:24.2972830","hpqpprop.exe","3796","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached","SUCCESS","Desired Access: Read" "18:53:24.2973542","hpqpprop.exe","3796","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached","SUCCESS","Desired Access: Read/Write" "18:53:29.0901385","hpqtbx01.exe","1476","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols","SUCCESS","Desired Access: All Access" "18:53:29.0903100","hpqtbx01.exe","1476","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols\HPZipm12.exe","SUCCESS","Desired Access: All Access" "18:53:29.1638174","hpqtbx01.exe","1476","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols","SUCCESS","Desired Access: All Access" "18:53:29.1638817","hpqtbx01.exe","1476","RegCreateKey","HKLM\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols\HPZipm12.exe","SUCCESS","Desired Access: All Access" "18:53:29.2294045","hpqtbx01.exe","1476","RegCreateKey","HKLM\System\CurrentControlSet\Control\DeviceClasses","SUCCESS","Desired Access: Read" "18:53:29.2735992","hpqtbx01.exe","1476","RegCreateKey","HKLM\System\CurrentControlSet\Control\DeviceClasses","SUCCESS","Desired Access: Read" "18:53:38.6601319","hpqpprop.exe","500","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:53:38.6602338","hpqpprop.exe","500","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b088-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:53:38.6638298","hpqpprop.exe","500","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}","SUCCESS","Desired Access: Maximum Allowed" "18:53:38.6639944","hpqpprop.exe","500","RegSetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e215b086-96e4-11db-bb65-806d6172696f}\BaseClass","SUCCESS","Type: REG_SZ, Length: 12, Data: Drive" "18:53:38.7525758","hpqpprop.exe","500","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked","SUCCESS","Desired Access: Read" "18:53:38.7526523","hpqpprop.exe","500","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked","SUCCESS","Desired Access: Read" "18:53:38.7528803","hpqpprop.exe","500","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached","SUCCESS","Desired Access: Read" "18:53:38.7529495","hpqpprop.exe","500","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached","SUCCESS","Desired Access: Read/Write" "18:53:49.9958737","hpqSTE08.exe","4008","RegCreateKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage","SUCCESS","Desired Access: Read, Set Value" "18:53:49.9960154","hpqSTE08.exe","4008","RegSetValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E1F1E18D4108346825DBA198A5D756\Usage\statusexe","SUCCESS","Type: REG_DWORD, Length: 4, Data: 964165651" "18:53:51.3240294","hpqdirec.exe","2512","RegCreateKey","HKCU\Software\Hewlett-Packard\DigitalImaging\Director","SUCCESS","Desired Access: Read/Write" "18:53:51.4210968","hpqdirec.exe","2512","RegSetValue","HKCU\Software\Hewlett-Packard\DigitalImaging\Director\CurrentDeviceNew","SUCCESS","Type: REG_SZ, Length: 102, Data: #Hewlett-Packard#HP Deskjet 6940 series#1227552509"